CRA-compliant,
with no blind spots.

Probenta watches your products, fires your regulatory notifications within the deadline and keeps your audit file ready to show.

Start the CRA self-assessment

Free, about 5 minutes. Your answers stay in your browser until you request your report — privacy.

Regulatory calendar — Regulation (EU) 2024/2847

Today

There are days left before the first deadline.

Pick a deadline to see what it requires.

11 Sept 2026

Article 14

Mandatory reporting of exploited vulnerabilities

As soon as a vulnerability in your product is actively exploited, a legal clock starts. Three deadlines follow, filed on ENISA's single reporting platform.

24 h
Early warning

Report the actively exploited vulnerability, without waiting for the analysis to be complete.

72 h
Full notification

Nature of the vulnerability, nature of the exploitation, corrective measures under way.

14 d
Final report

Once a fix is available: root cause, impact, measures taken.

“A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements […]”

11 Dec 2027

Articles 64 and 71

Full compliance and sanctions regime

The regulation applies in full. Without a compliant file, the CE marking no longer holds — and the sanctions regime becomes enforceable.

€15M
Maximum fines

Or 2.5% of total worldwide annual turnover, whichever is higher.

27
Markets closed

Without a compliant CE marking, no placing on the market in the Union.

Annex VII
Technical documentation

The file must exist, be kept up to date and be available on request.

Non-compliance with the essential requirements of Annex I and the obligations of Articles 13 and 14 is subject to administrative fines of up to €15,000,000 or, for an undertaking, 2.5% of its total worldwide annual turnover, whichever is higher.

The CRA is 81 dense pages in the Official Journal. Probenta turns them into the list of your obligations, product by product.
Discover the solution →

Feeds and sources monitored

CISA KEV  ·  CERT-FR  ·  ENISA (EUVD)  ·  NVD

What the CRA requires

01

The clock is ticking, you'll be notified in time

An exploited vulnerability starts a legal countdown. Miss it, and it is a sanction.

02

The technical file is a time sink.

Documentation, analyses, evidence: hours of engineering work, continuously.

03

Proving you notified on time.

Without a tamper-proof log, compliance cannot be demonstrated.

Simulation

One single data set. Multiple regulatory deliverables.

Evidence baseActive
SBOM
1 247 components tracked
Vulnerability feeds
18 correlated to your fleet
1 actively exploited — Art. 14 notification in progress
Art. 14 clocknot armedarmed
—:—:—Early warning · 24 h
Notification · 72 hFinal report · 14 d
CISA KEV · CERT-FR · EUVD · NVDCorrelated 2 min ago

A single entry feeds every deliverable

01 / 04

Article 14 notification

Pre-filled the moment you qualify it, ready to file within the deadline.

ProbentaNotification · Art. 14
CVE-2026-4471EARLY WARNING · 24 H—:—:—
ProductVaultGuard SIEM 4.2Auto
SeverityCritique · CVSS 9.1Auto
ExploitationConfirmée · CISA KEVAuto
TitleTo be writtenUnauthenticated remote code executionHuman

02 / 04

Annex VII technical file

Generated, kept up to date, ready for audit.

ProbentaDossier · Annexe VII
VaultGuard SIEM 4.2Généré le 04 juil. 2026
1Product descriptionUp to dateproduct sheet
2Cybersecurity risk assessmentUp to daterisk assessment
3SBOM & componentsUp to dateevidence base · 1,247 components
4Vulnerability handlingUp to dateArt. 14 log
5Support periodUp to dateproduct sheet
Annex VII · Regulation (EU) 2024/2847Every piece is drawn from the same data set. How do you assemble them today?

03 / 04

Disclosure portal

Your public reporting page, hosted by us.

04 / 04

Audit report

Every action time-stamped, ready to show the authority.

A mapping of your obligations, an evidence register.

A mapping of your obligations, an evidence register kept current.

01 — MAPPING

Your obligations, translated

Every CRA requirement becomes a traceable obligation, mapped to your products.

02 — EVIDENCE

A file that is always ready

Everything is centralized and versioned. The audit file exports in one click.

03 — MONITORING

The regulation moves, you keep up

You are alerted as soon as a regulatory change affects your scope.

04 — STEERING

Who delivers what, and by when

A dashboard per product and per milestone. Everyone knows what to deliver, and when.

Core of the product

Article 14 alarm

The full chain, from detection to proof of notification.

01 · CORRELATION

Your components, cross-checked against actively exploited vulnerabilities

02 · CLOCK

24 h / 72 h / 14 d, armed in one click on qualification

03 · NOTIFICATION

Pre-filled in the format ENISA publishes

04 · PROOF

Notification within the deadline, demonstrable

Included

Continuous monitoring

Your portfolio is continuously checked against exploited vulnerabilities.

Coming soon

Annex VII technical file

Generated and kept up to date automatically.

Coming soon

Hosted disclosure portal

Your reporting page, turnkey.

We never ingest your source code.

Your component inventory is all we need. Nothing else leaves your systems.

SBOM + metadata only

Hosted in the EU

Append-only audit log

GDPR compliant

Compliance

Our processors are European

Hosting, emailing, processors: our entire chain is European and GDPR compliant.

The details of our processing activities are in our privacy policy.

The CRA, and Probenta, in detail

What the regulation demands and how the product works.

What is the Cyber Resilience Act, and does it cover my product?
Regulation (EU) 2024/2847 sets cybersecurity requirements for every product with digital elements placed on the European market: software, connected devices, embedded components. If your product connects to a network, directly or indirectly, it is very likely in scope. Read the regulation →
What are the exact deadlines?
Two dates. On 11 September 2026, reporting actively exploited vulnerabilities becomes mandatory (Article 14). On 11 December 2027, the full set of requirements applies, including the sanctions regime: up to €15M or 2.5% of worldwide turnover (Article 64).
What is an SBOM, and how do I get one to you?
The Software Bill of Materials is the inventory of components — libraries, dependencies, versions — that make up your product. The CRA requires it in your technical documentation. Probenta generates it from your build pipeline, or takes an existing SBOM in the standard formats (CycloneDX, SPDX).
How do you detect the vulnerabilities that actually affect me?
We continuously cross-check your SBOM against catalogues of actively exploited vulnerabilities, notably CISA's KEV catalog and CERT-FR advisories. Only a vulnerability that genuinely touches a component in your portfolio raises an alert. We orchestrate proven open-source tools rather than an opaque proprietary engine.
What goes into an Article 14 notification?
Article 14 sets three deadlines. Two run from the moment you become aware of the actively exploited vulnerability: an early warning within 24 h, then a detailed notification within 72 h. The third starts elsewhere: the final report is due within 14 days after a corrective or mitigating measure becomes available — and within one month of the notification where a severe incident is concerned. These go to the coordinating CSIRT and ENISA. ENISA provides no machine interface: filing remains a human action on its form. Probenta arms the clock as soon as you qualify the alert and pre-fills what can be pre-filled; the fields that carry a judgement remain yours, prepared in advance rather than discovered against the clock.
How do I prove I notified on time?
Every action is written to an append-only log: entries are time-stamped and chained to one another, so none can be altered or removed after the fact. That log is what you present to the supervisory authority to demonstrate the notification went out on time.
What is the Annex VII technical file?
It is the documentation you must be able to produce at any time: product description, cybersecurity risk assessment, SBOM and components, vulnerability handling, support period. Probenta generates it from data you have already entered and keeps it current, rather than having you reconstruct a file the night before the audit.
Do you access my source code?
Never. Probenta processes only your SBOM and product metadata. Your code stays with you. This is an architectural choice: the less sensitive data we hold, the smaller your attack surface — and ours.
Where is my data hosted?
In France, on Scaleway, a French cloud provider certified ISO 27001. Our e-mails go through Brevo (Sendinblue SAS), also a French company. No data leaves the European Union. The details are in our privacy policy.
What is the real risk of non-compliance?
Two levels. The first is financial: up to €15M or 2.5% of worldwide turnover for failing the essential requirements. The second is commercial, and often heavier: without compliant CE marking, the product can no longer be placed on the European market.

A regulatory engineer, a security engineer

We combine regulatory expertise and software engineering to make the CRA manageable.

Ayoub Tougani

Software engineer and regulatory expert

Years in regulatory affairs and healthcare, now put to work automating compliance processes.

Alexandre Berthiot

Software and cybersecurity engineer

Seven years in healthcare, where product compliance is not negotiable, and a background in defensive security (blue team).

Let's talk about your deadline.

A quick conversation is enough to see where you stand. We get back to you within 72 business hours.

Based in
Nancy - France
Waitlist

* Required fields

No spam. We'll write when we open. By subscribing you agree we keep your information for this sole purpose — privacy.