What is NIS2? Am I affected? Sectors Frameworks: NIS2 Frameworks: Cyber Resilience Act Frameworks: ISO 27001 Pricing Free Guides Contact

CRA Incident & Vulnerability Reporting Readiness Pack

349,00 

  • 18 editable templates (15 Word + 3 Excel registers)
  • Both reporting tracks: 24h / 72h / 14-day & 1-month workflows
  • Pre-filled report forms + one-page reportability decision tree
  • ENISA submission guide, SBOM & CVD policies, 24-hour drill
  • Mapped to Regulation (EU) 2024/2847, Art. 14 & Annex I Part II
  • Instant download · Secured by Stripe

Licence scope: covers one legal entity. For multiple companies or client-delivery rights, see the Enterprise Licence (€997) — up to 5 organisations.

30-Day Update-or-Add Pledge: if a template needs adapting to your compliance environment — or your implementation calls for a document outside the standard scope — email info@nis-2-templates.com within 30 days and we’ll update it or add it. You keep everything either way.

Digital download — once you confirm at checkout, the EU 14-day withdrawal right is waived per Directive 2011/83/EU, Art. 16(m).

Description

From 11 September 2026, the day you discover one of your products is being actively exploited, you will have 24 hours to file an early warning — not 24 hours to fix it, 24 hours to report it. The CRA Reporting Readiness Pack hands you the 18 documents that decide whether your team meets that clock or misses it: a one-page reportability decision tree, pre-filled early-warning, 72-hour and final-report forms for both reporting tracks, the vulnerability-handling and SBOM foundations, an ENISA submission guide, a 24-hour drill, and a 90-day plan — each mapped to Article 14 and Annex I Part II of the EU Cyber Resilience Act (Regulation (EU) 2024/2847). You fill in your company details; the regulatory mapping is already done.

Mapped to Regulation (EU) 2024/2847, Art. 14
Both reporting tracks: 24h / 72h / 14-day & 1-month
18 templates · 15 Word + 3 Excel
Instant download · one-time €349
Get the Reporting Readiness Pack — €349

Want to see where you stand first? Run the free 10-minute CRA readiness self-assessment — no email wall to start.

The Clock Starts the Moment You Find Out — Not When You’re Ready

Here is the part most product teams have not internalised. Under Article 14, the 24-hour early-warning clock does not start when you have a fix, or when your legal team has reviewed it, or on Monday morning. It starts the moment you become aware that a vulnerability in your product is being actively exploited — and it does not pause for weekends, holidays, or time zones. Picture the alert landing at 5pm on a Friday. Who decides whether it is even reportable? Who drafts the early warning? Who is authorised to submit it before Saturday?

If you cannot answer those three questions today, you are not alone — and that is exactly the gap that turns a manageable vulnerability into a missed statutory deadline. The obligation applies from 11 September 2026, more than a year before the rest of the CRA, and non-compliance with the essential requirements, Article 13, or Article 14 can attract fines of up to €15,000,000 or 2.5% of total worldwide annual turnover, whichever is higher (Article 64). The regulation is not the hard part. The blank page is — every procedure you have not written, every form you would be drafting live while the clock runs.

You Shouldn’t Have to Draft Reporting Procedures During Your First Incident

The CRA Reporting Readiness Pack was built so you never face that blank page under pressure. You bring the knowledge of your own products; it brings the structure, the wording, and the regulatory mapping — so the first time your team fills in an early-warning report is a rehearsal, not a live exploit. Three documents do the heavy lifting the day it matters:

  • A one-page reportability decision tree — so the person holding the phone can tell, in minutes, whether this is an actively exploited vulnerability or a severe incident, and therefore which clock just started. Mixing up the two tracks is the single most common Article 14 error, because the headlines only ever say “24 and 72 hours.”
  • Pre-filled early-warning, 72-hour, and final-report forms for both tracks — you fill in the facts, not the structure, while the deadline runs.
  • An incident & reporting log with deadline-countdown columns — your evidence trail and your early-warning system against a missed filing.

What’s Inside: 18 Documents Across 4 Areas

Each document explains the legal requirement it implements, then gives you adaptable text with global placeholders ({{COMPANY_NAME}}, {{PRODUCT_NAME}}) you replace once across the whole pack. Organised so you can find what an auditor — or an incident — asks for in seconds:

Governance & scope · 4 docs

Applicability assessment (is each product in scope, and how is it classified?), the top-level reporting policy, and a RACI that names your CRA Compliance Officer, PSIRT Lead, deputies, and on-call rota — so someone owns the phone at 5pm on a Friday.

Vulnerability handling · 5 docs

Vulnerability handling procedure, coordinated disclosure (CVD) policy, a security contact & intake channel, the vulnerability register, and an SBOM policy (SPDX / CycloneDX) — the Annex I Part II foundation, without buying a scanner you do not need.

Reporting workflows · 5 docs

The 24h/72h/14-day exploited-vulnerability workflow, the 24h/72h/1-month severe-incident workflow, pre-filled report templates, the one-page reportability decision tree, and the deadline-countdown log.

Readiness & operations · 4 docs

An ENISA Single Reporting Platform submission guide, a ready-to-run 24-hour tabletop drill, a legacy product register (for products already on the market), and a 90-day plan that turns your gaps into a finished capability by the deadline.

See all 18 documents
# Document Format
00 Welcome & 30-Day Implementation Path DOCX
01 CRA Applicability Assessment DOCX
02 CRA Reporting Policy DOCX
03 Roles, Responsibilities & RACI DOCX
04 Vulnerability Handling Procedure DOCX
05 Coordinated Vulnerability Disclosure Policy DOCX
06 Security Contact & Vulnerability Intake DOCX
07 Vulnerability Register XLSX
08 SBOM Policy & Procedure DOCX
09 Actively Exploited Vulnerability Reporting Procedure DOCX
10 Severe Incident Reporting Procedure DOCX
11 Report Templates (Early Warning / Notification / Final) DOCX
12 Reportability Decision Tree DOCX
13 Incident & Reporting Log XLSX
14 Single Reporting Platform Submission Guide DOCX
15 Tabletop Exercise — 24-Hour Reporting Drill DOCX
16 Legacy Product Register XLSX
17 Readiness Checklist — 90-Day Plan DOCX

15 editable DOCX policies, procedures and guides + 3 XLSX registers. UK English. Version 1.1.

How You Get from Exposed to Reporting-Ready — in 3 Steps

  1. Download instantly. The moment your payment clears, all 18 documents are yours — no waiting, no onboarding call.
  2. Fill in your details and name your people. Replace the red placeholders with your company, products, and roles, and agree who sits on the on-call rota. The structure, the workflows, and the regulatory wording are already in place.
  3. Run the 24-hour drill. Put your team through the tabletop exercise once, on a quiet Tuesday, so that if a real exploit ever lands at 5pm on a Friday, they have done it before.

Four Ways to Get Reporting-Ready — Compared

  This Pack
€349
Write it yourself Hire a law firm Wait and see
Time to a working capability Days Weeks to months Weeks
Typical cost €349 one-time 40+ internal hours €5,000–€15,000+ Up to €15M / 2.5% if it goes wrong
Reportability decision tree Yes Rarely
Pre-filled 24h / 72h report forms Yes Sometimes
24-hour tabletop drill Yes
You keep and edit the documents Yes Yes Often licence-limited

Cost ranges are illustrative market figures, not quotes. The pack is a starting point you adapt — it does not replace legal advice where your situation needs it.

If This Is You, the Pack Was Built for You

You’re the compliance officer or CISO. You own CRA readiness and need a defensible, documented capability you can put in front of management and an auditor — on the day, not after a weekend of drafting. You’ll hand over an Article-14-mapped set of procedures with the regulatory references already embedded.

You’re the product security or PSIRT lead. You’ll be the one running the 24-hour clock. You’ll work from procedures, a decision tree, pre-filled forms, and an agreed rota — so your team knows who does what, and by when, before the first real incident.

You’re a hardware, software, or IoT manufacturer. If your product has digital elements and reaches the EU market, the CRA applies — whether you’re based in Munich, Austin, or Shenzhen. The pack is written for EU and non-EU manufacturers alike.

You have products already on the market. The Article 14 reporting duties reach legacy products too — not only those placed on the market after full application in December 2027. The included Legacy Product Register helps you track exactly which ones still carry the obligation.

Straight Answers Before You Buy

Is this legal advice?

No. These are professional working documents, not legal advice, and they do not guarantee compliance with the Cyber Resilience Act or any other law. Adapt every document to your organisation, products, and jurisdictions, and have your implementation reviewed by qualified legal counsel where appropriate. You remain solely responsible for your own compliance — what this pack removes is the blank page, not your judgement.

We’re a non-EU manufacturer (US / Asia). Does the CRA apply to us?

Yes, if you place a product with digital elements on the EU market. The CRA follows where the product is sold, not where the company is established. A US, UK, or Asian manufacturer selling into the EU carries the same Article 14 obligations as a German one — and the pack is written for exactly that reader.

Does this apply to products we already sell (legacy products)?

Yes. The Article 14 reporting obligations reach in-scope products already on the market, not only products placed on the market after full application in December 2027. The pack includes a dedicated Legacy Product Register to help you track them.

What format are the files, and can I edit them?

Fully editable Microsoft Word (DOCX) and Excel (XLSX) — 15 DOCX policies, procedures and guides plus 3 XLSX registers. The fields you complete (company name, product, roles, thresholds) render in red so nothing is missed; replace them once across the pack with search-and-replace. No locked PDFs, no proprietary software.

How current is this, and is the ENISA platform detail final?

The documents are mapped to Regulation (EU) 2024/2847, including Article 14, Article 16 (the single reporting platform), and Annex I Part II. Some operational details of the ENISA Single Reporting Platform are still being finalised by the authorities; where that is the case the documents flag the point as [TO BE CONFIRMED] — so you know exactly what to verify closer to the deadline, rather than trusting an invented specific.

What if a document doesn’t fit my environment?

This is a digital download, so the right of withdrawal is waived at checkout in accordance with EU Directive 2011/83/EU, Article 16(m) — you’ll be asked to consent to this before payment. To help you anyway, there’s a 30-day update-or-add pledge: if a template doesn’t fit your environment, email us within 30 days and we’ll update it — or add a document outside the standard scope. You keep everything either way.

What happens after I pay?

Instant download. You receive the full pack as a single ZIP (DOCX + XLSX) and an email receipt. One-time purchase, no subscription.

Walk Into 11 September 2026 Already Rehearsed

Picture the deadline arriving and nothing changing about your week — because the decision is already made. Your people are named, your decision tree is on the wall, your report forms are drafted, and your team has run the drill. If an exploit lands, you file the early warning inside 24 hours because you decided all of this on a quiet Tuesday, not at 5pm on a Friday. That is what the next step buys you.

Instant download after payment
Stripe-secured checkout
VAT handled at checkout
Editable DOCX + XLSX · no subscription
Get the Reporting Readiness Pack — €349

Deploying across several entities, or as a consultant serving clients? See the CRA Enterprise Licence (€997).

Reviews

There are no reviews yet.

Be the first to review “CRA Incident & Vulnerability Reporting Readiness Pack”

Your email address will not be published. Required fields are marked *