
CRA Incident & Vulnerability Reporting Readiness Pack
349,00 €
- 18 editable templates (15 Word + 3 Excel registers)
- Both reporting tracks: 24h / 72h / 14-day & 1-month workflows
- Pre-filled report forms + one-page reportability decision tree
- ENISA submission guide, SBOM & CVD policies, 24-hour drill
- Mapped to Regulation (EU) 2024/2847, Art. 14 & Annex I Part II
- Instant download · Secured by Stripe
Licence scope: covers one legal entity. For multiple companies or client-delivery rights, see the Enterprise Licence (€997) — up to 5 organisations.
30-Day Update-or-Add Pledge: if a template needs adapting to your compliance environment — or your implementation calls for a document outside the standard scope — email info@nis-2-templates.com within 30 days and we’ll update it or add it. You keep everything either way.
Digital download — once you confirm at checkout, the EU 14-day withdrawal right is waived per Directive 2011/83/EU, Art. 16(m).
Description
From 11 September 2026, the day you discover one of your products is being actively exploited, you will have 24 hours to file an early warning — not 24 hours to fix it, 24 hours to report it. The CRA Reporting Readiness Pack hands you the 18 documents that decide whether your team meets that clock or misses it: a one-page reportability decision tree, pre-filled early-warning, 72-hour and final-report forms for both reporting tracks, the vulnerability-handling and SBOM foundations, an ENISA submission guide, a 24-hour drill, and a 90-day plan — each mapped to Article 14 and Annex I Part II of the EU Cyber Resilience Act (Regulation (EU) 2024/2847). You fill in your company details; the regulatory mapping is already done.
Both reporting tracks: 24h / 72h / 14-day & 1-month
18 templates · 15 Word + 3 Excel
Instant download · one-time €349
Want to see where you stand first? Run the free 10-minute CRA readiness self-assessment — no email wall to start.
The Clock Starts the Moment You Find Out — Not When You’re Ready
Here is the part most product teams have not internalised. Under Article 14, the 24-hour early-warning clock does not start when you have a fix, or when your legal team has reviewed it, or on Monday morning. It starts the moment you become aware that a vulnerability in your product is being actively exploited — and it does not pause for weekends, holidays, or time zones. Picture the alert landing at 5pm on a Friday. Who decides whether it is even reportable? Who drafts the early warning? Who is authorised to submit it before Saturday?
If you cannot answer those three questions today, you are not alone — and that is exactly the gap that turns a manageable vulnerability into a missed statutory deadline. The obligation applies from 11 September 2026, more than a year before the rest of the CRA, and non-compliance with the essential requirements, Article 13, or Article 14 can attract fines of up to €15,000,000 or 2.5% of total worldwide annual turnover, whichever is higher (Article 64). The regulation is not the hard part. The blank page is — every procedure you have not written, every form you would be drafting live while the clock runs.
You Shouldn’t Have to Draft Reporting Procedures During Your First Incident
The CRA Reporting Readiness Pack was built so you never face that blank page under pressure. You bring the knowledge of your own products; it brings the structure, the wording, and the regulatory mapping — so the first time your team fills in an early-warning report is a rehearsal, not a live exploit. Three documents do the heavy lifting the day it matters:
- A one-page reportability decision tree — so the person holding the phone can tell, in minutes, whether this is an actively exploited vulnerability or a severe incident, and therefore which clock just started. Mixing up the two tracks is the single most common Article 14 error, because the headlines only ever say “24 and 72 hours.”
- Pre-filled early-warning, 72-hour, and final-report forms for both tracks — you fill in the facts, not the structure, while the deadline runs.
- An incident & reporting log with deadline-countdown columns — your evidence trail and your early-warning system against a missed filing.
What’s Inside: 18 Documents Across 4 Areas
Each document explains the legal requirement it implements, then gives you adaptable text with global placeholders ({{COMPANY_NAME}}, {{PRODUCT_NAME}}) you replace once across the whole pack. Organised so you can find what an auditor — or an incident — asks for in seconds:
Governance & scope · 4 docs
Applicability assessment (is each product in scope, and how is it classified?), the top-level reporting policy, and a RACI that names your CRA Compliance Officer, PSIRT Lead, deputies, and on-call rota — so someone owns the phone at 5pm on a Friday.
Vulnerability handling · 5 docs
Vulnerability handling procedure, coordinated disclosure (CVD) policy, a security contact & intake channel, the vulnerability register, and an SBOM policy (SPDX / CycloneDX) — the Annex I Part II foundation, without buying a scanner you do not need.
Reporting workflows · 5 docs
The 24h/72h/14-day exploited-vulnerability workflow, the 24h/72h/1-month severe-incident workflow, pre-filled report templates, the one-page reportability decision tree, and the deadline-countdown log.
Readiness & operations · 4 docs
An ENISA Single Reporting Platform submission guide, a ready-to-run 24-hour tabletop drill, a legacy product register (for products already on the market), and a 90-day plan that turns your gaps into a finished capability by the deadline.
See all 18 documents
| # | Document | Format |
|---|---|---|
| 00 | Welcome & 30-Day Implementation Path | DOCX |
| 01 | CRA Applicability Assessment | DOCX |
| 02 | CRA Reporting Policy | DOCX |
| 03 | Roles, Responsibilities & RACI | DOCX |
| 04 | Vulnerability Handling Procedure | DOCX |
| 05 | Coordinated Vulnerability Disclosure Policy | DOCX |
| 06 | Security Contact & Vulnerability Intake | DOCX |
| 07 | Vulnerability Register | XLSX |
| 08 | SBOM Policy & Procedure | DOCX |
| 09 | Actively Exploited Vulnerability Reporting Procedure | DOCX |
| 10 | Severe Incident Reporting Procedure | DOCX |
| 11 | Report Templates (Early Warning / Notification / Final) | DOCX |
| 12 | Reportability Decision Tree | DOCX |
| 13 | Incident & Reporting Log | XLSX |
| 14 | Single Reporting Platform Submission Guide | DOCX |
| 15 | Tabletop Exercise — 24-Hour Reporting Drill | DOCX |
| 16 | Legacy Product Register | XLSX |
| 17 | Readiness Checklist — 90-Day Plan | DOCX |
15 editable DOCX policies, procedures and guides + 3 XLSX registers. UK English. Version 1.1.
How You Get from Exposed to Reporting-Ready — in 3 Steps
- Download instantly. The moment your payment clears, all 18 documents are yours — no waiting, no onboarding call.
- Fill in your details and name your people. Replace the red placeholders with your company, products, and roles, and agree who sits on the on-call rota. The structure, the workflows, and the regulatory wording are already in place.
- Run the 24-hour drill. Put your team through the tabletop exercise once, on a quiet Tuesday, so that if a real exploit ever lands at 5pm on a Friday, they have done it before.
Four Ways to Get Reporting-Ready — Compared
| This Pack €349 |
Write it yourself | Hire a law firm | Wait and see | |
|---|---|---|---|---|
| Time to a working capability | Days | Weeks to months | Weeks | — |
| Typical cost | €349 one-time | 40+ internal hours | €5,000–€15,000+ | Up to €15M / 2.5% if it goes wrong |
| Reportability decision tree | Yes | — | Rarely | — |
| Pre-filled 24h / 72h report forms | Yes | — | Sometimes | — |
| 24-hour tabletop drill | Yes | — | — | — |
| You keep and edit the documents | Yes | Yes | Often licence-limited | — |
Cost ranges are illustrative market figures, not quotes. The pack is a starting point you adapt — it does not replace legal advice where your situation needs it.
If This Is You, the Pack Was Built for You
You’re the compliance officer or CISO. You own CRA readiness and need a defensible, documented capability you can put in front of management and an auditor — on the day, not after a weekend of drafting. You’ll hand over an Article-14-mapped set of procedures with the regulatory references already embedded.
You’re the product security or PSIRT lead. You’ll be the one running the 24-hour clock. You’ll work from procedures, a decision tree, pre-filled forms, and an agreed rota — so your team knows who does what, and by when, before the first real incident.
You’re a hardware, software, or IoT manufacturer. If your product has digital elements and reaches the EU market, the CRA applies — whether you’re based in Munich, Austin, or Shenzhen. The pack is written for EU and non-EU manufacturers alike.
You have products already on the market. The Article 14 reporting duties reach legacy products too — not only those placed on the market after full application in December 2027. The included Legacy Product Register helps you track exactly which ones still carry the obligation.
Straight Answers Before You Buy
Is this legal advice?
No. These are professional working documents, not legal advice, and they do not guarantee compliance with the Cyber Resilience Act or any other law. Adapt every document to your organisation, products, and jurisdictions, and have your implementation reviewed by qualified legal counsel where appropriate. You remain solely responsible for your own compliance — what this pack removes is the blank page, not your judgement.
We’re a non-EU manufacturer (US / Asia). Does the CRA apply to us?
Yes, if you place a product with digital elements on the EU market. The CRA follows where the product is sold, not where the company is established. A US, UK, or Asian manufacturer selling into the EU carries the same Article 14 obligations as a German one — and the pack is written for exactly that reader.
Does this apply to products we already sell (legacy products)?
Yes. The Article 14 reporting obligations reach in-scope products already on the market, not only products placed on the market after full application in December 2027. The pack includes a dedicated Legacy Product Register to help you track them.
What format are the files, and can I edit them?
Fully editable Microsoft Word (DOCX) and Excel (XLSX) — 15 DOCX policies, procedures and guides plus 3 XLSX registers. The fields you complete (company name, product, roles, thresholds) render in red so nothing is missed; replace them once across the pack with search-and-replace. No locked PDFs, no proprietary software.
How current is this, and is the ENISA platform detail final?
The documents are mapped to Regulation (EU) 2024/2847, including Article 14, Article 16 (the single reporting platform), and Annex I Part II. Some operational details of the ENISA Single Reporting Platform are still being finalised by the authorities; where that is the case the documents flag the point as [TO BE CONFIRMED] — so you know exactly what to verify closer to the deadline, rather than trusting an invented specific.
What if a document doesn’t fit my environment?
This is a digital download, so the right of withdrawal is waived at checkout in accordance with EU Directive 2011/83/EU, Article 16(m) — you’ll be asked to consent to this before payment. To help you anyway, there’s a 30-day update-or-add pledge: if a template doesn’t fit your environment, email us within 30 days and we’ll update it — or add a document outside the standard scope. You keep everything either way.
What happens after I pay?
Instant download. You receive the full pack as a single ZIP (DOCX + XLSX) and an email receipt. One-time purchase, no subscription.
Walk Into 11 September 2026 Already Rehearsed
Picture the deadline arriving and nothing changing about your week — because the decision is already made. Your people are named, your decision tree is on the wall, your report forms are drafted, and your team has run the drill. If an exploit lands, you file the early warning inside 24 hours because you decided all of this on a quiet Tuesday, not at 5pm on a Friday. That is what the next step buys you.
Stripe-secured checkout
VAT handled at checkout
Editable DOCX + XLSX · no subscription
Deploying across several entities, or as a consultant serving clients? See the CRA Enterprise Licence (€997).
Disclaimer: These templates are general samples for internal use. They do not constitute legal advice and must be reviewed by a qualified professional before adoption. No document in this pack guarantees compliance with the Cyber Resilience Act. See our full Disclaimer.


Reviews
There are no reviews yet.