CRA-compliant,
with no blind spots.
Probenta watches your products, fires your regulatory notifications within the deadline and keeps your audit file ready to show.
Free, about 5 minutes. Your answers stay in your browser until you request your report — privacy.
Regulatory calendar — Regulation (EU) 2024/2847
Today
There are days left before the first deadline.
Pick a deadline to see what it requires.
11 Sept 2026
Article 14
Mandatory reporting of exploited vulnerabilities
As soon as a vulnerability in your product is actively exploited, a legal clock starts. Three deadlines follow, filed on ENISA's single reporting platform.
Report the actively exploited vulnerability, without waiting for the analysis to be complete.
Nature of the vulnerability, nature of the exploitation, corrective measures under way.
Once a fix is available: root cause, impact, measures taken.
“A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements […]”
11 Dec 2027
Articles 64 and 71
Full compliance and sanctions regime
The regulation applies in full. Without a compliant file, the CE marking no longer holds — and the sanctions regime becomes enforceable.
Or 2.5% of total worldwide annual turnover, whichever is higher.
Without a compliant CE marking, no placing on the market in the Union.
The file must exist, be kept up to date and be available on request.
Non-compliance with the essential requirements of Annex I and the obligations of Articles 13 and 14 is subject to administrative fines of up to €15,000,000 or, for an undertaking, 2.5% of its total worldwide annual turnover, whichever is higher.
Feeds and sources monitored
CISA KEV · CERT-FR · ENISA (EUVD) · NVD
What the CRA requires
01
The clock is ticking, you'll be notified in time
An exploited vulnerability starts a legal countdown. Miss it, and it is a sanction.
02
The technical file is a time sink.
Documentation, analyses, evidence: hours of engineering work, continuously.
03
Proving you notified on time.
Without a tamper-proof log, compliance cannot be demonstrated.
One single data set. Multiple regulatory deliverables.
A single entry feeds every deliverable
01 / 04
Article 14 notification
Pre-filled the moment you qualify it, ready to file within the deadline.
02 / 04
Annex VII technical file
Generated, kept up to date, ready for audit.
03 / 04
Disclosure portal
Your public reporting page, hosted by us.
04 / 04
Audit report
Every action time-stamped, ready to show the authority.
A mapping of your obligations, an evidence register.
A mapping of your obligations, an evidence register kept current.
Your obligations, translated
Every CRA requirement becomes a traceable obligation, mapped to your products.
A file that is always ready
Everything is centralized and versioned. The audit file exports in one click.
The regulation moves, you keep up
You are alerted as soon as a regulatory change affects your scope.
Who delivers what, and by when
A dashboard per product and per milestone. Everyone knows what to deliver, and when.
Article 14 alarm
The full chain, from detection to proof of notification.
01 · CORRELATION
Your components, cross-checked against actively exploited vulnerabilities
02 · CLOCK
24 h / 72 h / 14 d, armed in one click on qualification
03 · NOTIFICATION
Pre-filled in the format ENISA publishes
04 · PROOF
Notification within the deadline, demonstrable
Included
Continuous monitoring
Your portfolio is continuously checked against exploited vulnerabilities.
Coming soon
Annex VII technical file
Generated and kept up to date automatically.
Coming soon
Hosted disclosure portal
Your reporting page, turnkey.
We never ingest your source code.
Your component inventory is all we need. Nothing else leaves your systems.
SBOM + metadata only
Hosted in the EU
Append-only audit log
GDPR compliant
Our processors are European
Hosting, emailing, processors: our entire chain is European and GDPR compliant.
Scaleway
French cloud provider, ISO 27001 certified.
Scaleway security & certifications →Plausible
Site statistics with no cookies and no personal data, hosted in the EU.
Plausible & privacy →GDPR end to end
Data minimisation, EU hosting, rights you can exercise at any time.
Read Regulation (EU) 2016/679 →The details of our processing activities are in our privacy policy.
The CRA, and Probenta, in detail
What the regulation demands and how the product works.
What is the Cyber Resilience Act, and does it cover my product?
What are the exact deadlines?
What is an SBOM, and how do I get one to you?
How do you detect the vulnerabilities that actually affect me?
What goes into an Article 14 notification?
How do I prove I notified on time?
What is the Annex VII technical file?
Do you access my source code?
Where is my data hosted?
What is the real risk of non-compliance?
A regulatory engineer, a security engineer
We combine regulatory expertise and software engineering to make the CRA manageable.
Ayoub Tougani
Years in regulatory affairs and healthcare, now put to work automating compliance processes.
Alexandre Berthiot
Seven years in healthcare, where product compliance is not negotiable, and a background in defensive security (blue team).
Let's talk about your deadline.
A quick conversation is enough to see where you stand. We get back to you within 72 business hours.
No spam. We'll write when we open. By subscribing you agree we keep your information for this sole purpose — privacy.