Assess readiness for EU CRA Article 14 vulnerability reporting obligations: capability to detect actively exploited vulnerabilities, the 24-hour early warning process, 72-hour notification to CSIRT/ENISA, endpoint configuration, and a coordinated disclosure policy. Vulnerability reporting obligations apply from 11 Sep 2026 — earlier than the main CRA applicability date.
🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
⏱ CRA Article 14 vulnerability reporting timeline: 24 hours — early warning to national CSIRT (or ENISA) for actively exploited vulnerabilities. 72 hours — full notification with severity assessment and corrective measures. Full applicability 11 Dec 2027; Art. 14 reporting applies from 11 Sep 2026.
Scope
Terminal node of the cra-product-conformance chain (art-138→139→140). Assesses operational readiness for CRA Article 14 vulnerability disclosure obligations. All five capabilities must be in place: a detection process for actively exploited vulnerabilities, 24-hour early-warning workflow, 72-hour full notification workflow, CSIRT/ENISA reporting endpoint configured, and a published coordinated disclosure policy. Non-compliance from Sep 2026.
Copy this paragraph into Claude, OpenClaw, or any MCP-aware agent to run this exact tool, with this sample, and verify the artifact.
Run the AINumbers MCP tool `assess_cra_vuln_reporting_readiness`. Task: Assess EU CRA Article 14 vulnerability reporting readiness: actively_exploited_detection, early_warning_24h_process, notification_72h_process, csirt_enisa_endpoint_configured, coordinated_disclosure_policy.
Call it with arguments: {"policy_parameters":{"actively_exploited_detection":true,"early_warning_24h_process":true,"notification_72h_process":true,"csirt_enisa_endpoint_configured":true,"coordinated_disclosure_policy":true}}
Verify before trusting: call `verify_execution_hash` on mcp.ainumbers.co (https://mcp.ainumbers.co/mcp) with the parameter `claimed_hash` set to the returned `execution_hash`, passing the full artifact the run returned (the object containing `policy_parameters` + `output_payload` + `execution_hash`; equivalently `policy_parameters` + `output_payload` with `claimed_hash`), not the bare hash string, or re-run the in-page WebMCP tool `assess_cra_vuln_reporting_readiness`.
Return the ledger link https://ledger.ainumbers.co/ so a human can re-verify without contacting us.
PII rule: All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
Open the tool with the sample prefilled: https://ainumbers.co/chaingraph/art-140-cra-vuln-reporting-readiness.html#p=v1.H4sIAAAAAAAA_wGyAE3_eyJhY3RpdmVseV9leHBsb2l0ZWRfZGV0ZWN0aW9uIjp0cnVlLCJlYXJseV93YXJuaW5nXzI0aF9wcm9jZXNzIjp0cnVlLCJub3RpZmljYXRpb25fNzJoX3Byb2Nlc3MiOnRydWUsImNzaXJ0X2VuaXNhX2VuZHBvaW50X2NvbmZpZ3VyZWQiOnRydWUsImNvb3JkaW5hdGVkX2Rpc2Nsb3N1cmVfcG9saWN5Ijp0cnVlfaOfESmyAAAA