cra-incident-clocks

Generate schema-conformant JSON reports for EU Cyber Resilience Act Article 14 incident filings.

3|2|Updated Jan 23, 2026
One-click install
npx skills add https://github.com/robotijn/ctoc --skill cra-incident-clocks
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cra-incident-clocks
Source: https://github.com/robotijn/ctoc/tree/main/skills/security/cra-incident-clocks
Command: npx skills add https://github.com/robotijn/ctoc --skill cra-incident-clocks

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

EU manufacturers, importers, and distributors of products with digital elements face strict statutory deadlines for reporting actively exploited vulnerabilities and severe security incidents under the EU Cyber Resilience Act (CRA) Article 14, with fines of up to 2.5% of global annual turnover for late, incomplete, or missing filings. Manually tracking the 24-hour, 72-hour, and 14-day reporting clocks, plus populating all required ENISA single reporting platform fields, is error-prone and high-risk for compliance teams.

Core Features & Use Cases

  • Statutory Clock Tracking: Automates tracking of the three mandatory CRA Article 14 reporting deadlines (24-hour early warning, 72-hour notification, 14-day final report) from the moment of organizational awareness, with clear workflow steps for each submission type and mandatory 30-day handling report for unresolved incidents.
  • ENISA Conformant Reporting: Generates pre-populated, schema-valid JSON for all CRA Article 14 report types, including all required fields for the ENISA single reporting platform, with support for unknown field justification and superseding report linkage for amended filings.
  • Use Case: A SaaS company discovers an actively exploited zero-day vulnerability in their EU-distributed mobile application; use this skill to file the 24-hour early warning within the statutory window, update it with full details at 72 hours, and submit the final report once a patch is released, avoiding costly regulatory penalties.

Quick Start

Use the cra-incident-clocks skill to file a 24-hour early warning report for the actively exploited CVE-2026-XXXXX vulnerability affecting your EU-distributed product, including all required ENISA platform fields and audit log entries.

Frequently Asked Questions about cra-incident-clocks

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What are the CRA Article 14 incident reporting deadlines for actively exploited vulnerabilities?

CRA Article 14 incident reporting requires submitting an early warning within 24 hours, a notification within 72 hours, and a final report within 14 days of organizational awareness. This skill automates tracking these statutory clocks and populates required ENISA platform fields for compliance.

How do I generate ENISA schema-conformant JSON for Cyber Resilience Act vulnerability reports?

To generate ENISA schema-conformant JSON for Cyber Resilience Act vulnerability reports, use this skill to pre-populate all mandatory fields for early warnings, notifications, and final reports. It ensures schema validity and supports superseding report linkage for amended filings.

Can I file amended CRA Article 14 reports if new vulnerability information becomes available?

Yes, you can file amended CRA Article 14 reports using superseding report linkage. This skill supports generating updated ENISA submissions that link to original filings, ensuring audit-logged compliance when new vulnerability details emerge after the initial 24-hour or 72-hour deadlines.

Does this tool support Software Bill of Materials integration for cross-border incident assessment?

Yes, this tool supports Software Bill of Materials integration and cross-border impact assessment for CRA Article 14 reporting. It helps manufacturers, importers, and distributors identify affected components and assess multi-jurisdictional impact when filing reports to the ENISA single reporting platform.

What happens if I miss a 24-hour or 72-hour CRA vulnerability notification deadline?

Missing a 24-hour or 72-hour CRA vulnerability notification deadline risks fines up to 2.5% of global annual turnover for incomplete filings. This skill automates statutory clock tracking from organizational awareness to prevent late, missing, or non-compliant ENISA submissions.