Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How does ShipReady Metrics support CRA readiness and evidence collection?
Last verifiedShipReady Metrics maps signed-in surfaces to Regulation (EU) 2024/2847 Article 14 and Annex I: the CRA reporting ladder, vulnerability intake, SBOM, and evidence collection. It prepares named-reviewer drafts. A named human still submits. This page is not legal advice and does not start a clock.
How ShipReady Metrics supports CRA readiness, last verified 9 September 2026 against Regulation (EU) 2024/2847 Articles 13, 14, 16, 31 and 71, Annex I and Annex VII, the European Commission's CRA policy page (Commission materials — guidance, not the regulation), and ENISA product-security / Single Reporting Platform materials (agency guidance, not the regulation). It is not legal advice, not a filing, not a determination that the CRA applies, not CE marking, and not a substitute for counsel. SRM prepares, you decide/submit.
This is a capability map, not YOUR determination
Audience: a CISO, CTO, or compliance owner evaluating whether this product's shipped surfaces help CRA readiness work. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the CRA applies, that you are a manufacturer, that a product with digital elements has been made available on the Union market, that a reporting clock has started, or that essential requirements are met.
The CRA is Regulation (EU) 2024/2847 of 23 October 2024, OJ L 2024/2847, 20.11.2024. ELI: http://data.europa.eu/eli/reg/2024/2847/2024-11-20. It is a regulation, directly applicable. Using this product is not CRA conformity, not CE marking, and not a market-surveillance determination. Last verified 9 September 2026. Not legal advice.
- Statute versus guidance versus this product: Articles 13, 14, 16, 31 and 71, and Annex I and Annex VII, are legal requirements only if they apply. Commission CRA pages are Commission materials — guidance, not the regulation. ENISA product-security and Single Reporting Platform materials are agency guidance, not the regulation. The mapping table quotes which kind of text each row relies on, including SRM recommendation where the row is a product practice rather than an article.
- The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page. The SaaS-scope guide on this site is the remote-processing versus service page. The CRA-cluster Article 14 overview on this site is the cluster reporting page. The statute-clock Article 14 guide on this site is the ladder under breach reporting. The where-to-submit guide on this site is the Article 14 channel page. The ENISA-workflow guide on this site is the platform-flow page. The CSIRT guide on this site is the coordinator-interaction page. The coordinated-vulnerability-disclosure guide on this site is the Annex I Part II CVD page. The evidence-retention guide on this site is the technical-documentation keep page. The readiness-checklist guide on this site is the end-to-end CRA readiness page.
- A dedicated products-in-scope, 24-hour-early-warning, 72-hour-notification, final-report, actively-exploited, vulnerability-management, security-updates, penalties, decision-tree, and incident-example guide is not on this site yet. Naming them is not a link.
Capability-to-obligation mapping — not a determination
The table maps shipped product surfaces to CRA obligation areas. It is an aid for deciding where the product prepares work and where people and counsel still act. It is not YOUR file, not a finding that any row applies, and not marketing copy. Checking a row here does not mean the organisation is CRA-conformant. Last verified 9 September 2026. Not legal advice.
| Area | Product surface | What it prepares | What you still do | Kind of text |
|---|---|---|---|---|
| Article 14 reporting | Signed-in app → Compliance → CRA reporting. Named-reviewer drafts for the 24-hour early warning, 72-hour notification, and 14-day final report from recorded awareness, and the 14-day mark from recorded measure availability, for findings the organisation classified as CRA-in-scope. | A DRAFT body a named reviewer can take into the ENISA single reporting platform. Status is the literal 'draft'. The shape carries no submission field. Unknown manufacturer, product, or Member-State list renders TO BE COMPLETED BY REVIEWER, never a guess. | Decide whether Article 14 applies, whether you have become aware, and whether a finding is an actively exploited vulnerability or a severe incident. A named human still submits to the CSIRT designated as coordinator and to ENISA. This product does not start an Article 14 clock and does not file. | Legal requirement — Articles 14, 16, 69(3) and 71(2). Only if the CRA applies. This page does not start that clock. |
| Vulnerability handling | Signed-in Security → Findings. Connector-ingested alerts (Dependabot / SCA, SAST / code scanning, DAST, secret scanning), ranked with CISA KEV, EPSS, and CVSS, with distinct-vulnerability dedup and blast-radius search over captured dependencies. | Intake, ranking, and package-exposure search for repositories the organisation connected. A KEV match timestamp is disclosure, not the Article 14 clock. | Run YOUR vulnerability-handling process, decide awareness, publish a coordinated vulnerability disclosure policy, and provide security updates. A dedicated vulnerability-management and security-updates guide is not on this site yet. Naming them is not a link. | Legal requirement for handling without delay and security updates — Article 13(8) and Annex I Part II, from 11 December 2027 (Article 71(2)). KEV / EPSS / CVSS ranking is best practice, not the Article 14 trigger. Article 14(1) is awareness of an actively exploited vulnerability as Article 3(42) defines it, not a KEV listing. |
| SBOM / component inventory | CycloneDX generation and blast-radius queries over captured dependencies (transitive npm when a lockfile was fetched). Annex I-II(1) in the cra starter control-set is labelled component inventory (SBOM). | A generated SBOM and package-exposure search for captured repositories. Those records are retained evidence in this product. | Keep YOUR CRA SBOM at the disposal of market surveillance authorities as part of technical documentation. A generated CycloneDX file here is not Annex VII point 2(b) and not a 10-year keep. | Legal requirement — Annex I Part II component inventory, from 11 December 2027 (Article 71(2)). Only if the manufacturer duty applies. |
| Evidence collection and review | Signed-in Compliance evidence collection (control-mapped artifacts) and a human evidence review overlay (accept can render a manual row as met; reject as gap). | Timestamped evidence records for the cra starter subset and the CRA-to-canonical-control crosswalk. The met-verdict overlay is a compliance artifact. | Draw up and keep the Article 31 / Annex VII technical documentation and the EU declaration of conformity. This product does not retain YOUR CRA technical documentation pack automatically and is not a 10-year Article 13(13) keep. The evidence-retention guide on this site is the keep-period page. | Legal requirement — Articles 13(13), 31 and Annex VII, from 11 December 2027 except where Article 14 already applies. The met-verdict overlay is an SRM recommendation for control-mapped evidence, not Annex VII. |
| Framework crosswalk and obligation map | Bundled framework key cra, customer-visible, version label Regulation (EU) 2024/2847 (starter subset), not in INTERNAL_TESTER_ONLY_FRAMEWORKS. Obligation map lists frameworks the organisation marked in-scope. A CRA-to-canonical-control crosswalk exists in the signed-in compliance layer. | An illustrative readiness mapping and an in-scope mark the organisation can set. nis2 is also customer-visible. Keys dpdp, uae_pdpl, difc_dp, and adgm_dpr are INTERNAL_TESTER_ONLY; they are not this page. | Decide whether the CRA applies and whether you are a manufacturer. Marking cra in-scope is not that determination and does not complete readiness. Tailor the starter subset. Counsel applies Articles 2 and 3 to YOUR facts. | SRM recommendation — illustrative readiness mapping, to be tailored; not legal advice; not full conformity-assessment detail. Not a legal requirement. |
| Coordinated vulnerability disclosure policy hosting | Policies Library can host a policy document the organisation already wrote. | A hosted copy inside the signed-in library. | Write, publish, and keep reachable the coordinated vulnerability disclosure policy and the contact address Annex I Part II points (5) and (6) and Annex II point 2 name. Hosting a file here is not publishing that policy and is not YOUR public reporter mailbox. The coordinated-vulnerability-disclosure guide on this site is the Annex I Part II CVD page. | Legal requirement — Article 13(8) and Annex I Part II points (5) and (6), from 11 December 2027. Hosting in this product is an SRM recommendation, not that publication. |
| Single reporting platform channel | No submit button. No ENISA API. Compliance → CRA reporting is a named-reviewer draft only. | Draft text a human can type into the platform ENISA establishes under Article 16. | Create the Assigned Representative, use EU Login, and submit on the platform. The where-to-submit guide on this site is the Article 14 channel page. The ENISA-workflow guide on this site is the platform-flow page. A dedicated 24-hour-early-warning, 72-hour-notification, final-report, and actively-exploited guide is not on this site yet. Naming them is not a link. | Article 16 is a legal requirement. ENISA SRP pages are agency guidance, not the regulation. Commission CRA reporting pages are Commission materials — guidance, not the regulation. |
SRM prepares, you decide/submit
The boundary is the point of this page. ShipReady Metrics prepares named-reviewer drafts, control-mapped evidence rows, an illustrative cra mapping, vulnerability intake, and SBOM records for captured repositories. You decide whether a duty applies. A named human still submits. Last verified 9 September 2026. Not legal advice.
- Prepares: a DRAFT Article 14 ladder from recorded awareness for findings the organisation classified as CRA-in-scope; KEV / EPSS / CVSS-ranked findings with dedup and blast radius; CycloneDX SBOM and dependency ingest; evidence collection and the met-verdict overlay; the cra starter subset and crosswalk.
- Does not decide: that the CRA applies; that you are a manufacturer; that a product with digital elements has been made available on the Union market; that you have become aware; that a finding is an actively exploited vulnerability under Article 3(42) or a severe incident under Article 14(5); that essential requirements are met.
- Does not start an Article 14 clock. Recorded awareness is a human determination the platform must not backdate. Opening the ladder, classifying a finding as CRA-in-scope, matching KEV, or reading this page does not start that clock.
- Does not file with a CSIRT or ENISA. There is no submit button. The SRP has no API in this design. A named human still types the filing. Status on a draft is the literal 'draft'.
- Readiness in this product is not CE marking, not an EU declaration of conformity, and not a market-surveillance determination. The in-scope mark is not a determination.
Article 14 ladder honesty
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organisation classified as CRA-in-scope. Each draft is marked DRAFT and states that a named reviewer must verify and submit; nothing in that surface has been sent to any authority.
That tracker does not start an Article 14 clock, does not decide that the CRA applies, and does not file with a CSIRT or ENISA. A named human still submits. A KEV match timestamp is disclosure, not the clock. Article 14 applies from 11 September 2026 (Article 71(2)); full essential-requirements application remains 11 December 2027. Those two dates are not one number. This page does not start that clock.
The statute-clock Article 14 guide on this site is the live ladder under breach reporting. The CRA-cluster Article 14 overview on this site is the cluster page. Those two pages agree on the marks. This page does not invent a second set of clocks. A dedicated 24-hour-early-warning, 72-hour-notification, final-report, actively-exploited, decision-tree, and incident-example guide is not on this site yet. Naming them is not a link.
Evidence and named-reviewer overlay honesty
Compliance evidence collection records control-mapped artifacts for a starter subset. The human evidence review overlay can accept a manual row as met or reject it as a gap. That met-verdict overlay is a compliance artifact for SOC 2 / ISO 27001-style programs — a timestamped evidence record for controls. It is not Annex VII technical documentation, not an EU declaration of conformity, and not a 10-year keep under Article 13(13).
SBOM and vulnerability records exist: CycloneDX generation, blast-radius queries, and connector-ingested findings. Those records are retained evidence in this product. They are not YOUR CRA SBOM kept at the disposal of market surveillance authorities, and they are not a substitute for Annex VII. The evidence-retention guide on this site is the keep-period page.
The named-reviewer overlay on CRA drafts is a product rule for those drafts: a named reviewer must verify and submit. It is not a notified-body review, not a conformity-assessment module, and not CE marking.
Framework crosswalk honesty
The bundled framework key cra is customer-visible. Its version label is Regulation (EU) 2024/2847 (starter subset). It is not in INTERNAL_TESTER_ONLY_FRAMEWORKS. The control-set is a starter subset, illustrative readiness mapping, to be tailored by a compliance owner; not legal advice; not full conformity-assessment detail. Readiness is not compliance, not CE marking, and not a market-surveillance determination.
A CRA-to-canonical-control crosswalk exists in the signed-in compliance layer. That crosswalk is an illustrative mapping, not a determination, not a count of CRA-conformant controls, and not CE marking. The obligation map lists frameworks the organisation has marked in-scope, including cra if that mark is set. Marking cra in-scope is not a determination that you are a manufacturer or that a product with digital elements has been made available on the Union market, and it does not complete readiness.
The bundled key nis2 is also customer-visible. Keys dpdp, uae_pdpl, difc_dp, and adgm_dpr are INTERNAL_TESTER_ONLY; customer surfaces hide them. This page is not a DPDP, UAE PDPL, DIFC, or ADGM guide. The cyber risk register lives under Security. It is not an Article 14 file.
What to do now
As of last verification on 9 September 2026, Article 14 applies from 11 September 2026 — two days from that verification date. Full essential-requirements application remains 11 December 2027. The list below is operational preparation. It is not a determination that the CRA applies to YOU, that you are a manufacturer, or that a reporting clock has started. Walk it with counsel.
- Ask counsel whether YOU are a manufacturer of a product with digital elements made available on the Union market. This page does not run that test. Marking cra in-scope on the obligation map is not that determination.
- If counsel says Article 14 may apply, open the statute-clock Article 14 guide on this site for the 24-hour / 72-hour / 14-day ladder, or the CRA-cluster Article 14 overview. Treat Compliance → CRA reporting as a named-reviewer draft from recorded awareness, not as a filing and not as a clock this product starts. A named human still submits.
- If counsel says Annex I Part II may apply, walk the coordinated-vulnerability-disclosure guide on this site for the CVD policy and contact address, and the evidence-retention guide on this site for the keep. A dedicated vulnerability-management and security-updates guide is not on this site yet. Naming them is not a link.
- Do not treat a KEV listing as automatic becoming-aware. Do not treat a met verdict as Annex VII. Do not treat the cra starter subset as a conformity-assessment file. Do not treat readiness in this product as CE marking.
- The readiness-checklist guide on this site is the end-to-end CRA readiness page. A dedicated products-in-scope, penalties, decision-tree, and incident-example guide is not on this site yet. Naming them is not a link.
Primary sources (last verified 9 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/2847 of 23 October 2024 (Cyber Resilience Act), Articles 13, 14, 16, 31 and 71 and Annex I and Annex VII, is a legal requirement only if it applies. Article 14 reporting applies from 11 September 2026; Chapter IV from 11 June 2026; the rest, including essential cybersecurity requirements, from 11 December 2027 (Article 71(2)). Entry into force was 10 December 2024 (Article 71(1)). The European Commission's CRA policy page and CRA reporting page are Commission materials, not the regulation. ENISA's product-security pages and Single Reporting Platform materials are agency guidance, not the regulation. These are not a complete world list. Not legal advice.
The CRA overview on this site is the pillar page. The statute-clock Article 14 guide on this site is the live ladder under breach reporting. The CRA-cluster Article 14 overview on this site is the cluster page. The who-is-covered guide on this site is the economic-operator roles page. The SaaS-scope guide on this site is the remote-processing versus service page. The where-to-submit guide on this site is the Article 14 channel page. The ENISA-workflow guide on this site is the platform-flow page. The CSIRT guide on this site is the coordinator-interaction page. The coordinated-vulnerability-disclosure guide on this site is the Annex I Part II CVD page. The evidence-retention guide on this site is the technical-documentation keep page. The readiness-checklist guide on this site is the end-to-end CRA readiness page. A dedicated products-in-scope, 24-hour-early-warning, 72-hour-notification, final-report, actively-exploited, vulnerability-management, security-updates, penalties, decision-tree, and incident-example guide is not on this site yet. Naming them is not a link.