Documentation menu

Guides

CRA reporting

How boring.tools opens a case when a vulnerability in your product is actively exploited, and keeps track of the Art. 14 deadlines.

Since 11 September 2026, the EU Cyber Resilience Act (Art. 14) requires manufacturers to report actively exploited vulnerabilities in their products to the responsible CSIRT and ENISA, through ENISA’s Single Reporting Platform. boring.tools notices when that happens, starts the clock and keeps a record of what you reported. Submitting the report itself is done by you on the platform.

When a case opens

Every ten minutes boring.tools checks the latest analysis of every version of every project — also versions whose support period has ended, because the reporting duty outlives support. When a finding’s CVE is listed as actively exploited in CISA KEV or ENISA EUVD, it opens one case per project and vulnerability, listing every affected version, artifact and component. Later versions with the same vulnerability join the existing case.

The clock starts at detection: we treat the moment boring.tools knows about it as the moment you became aware. That is the cautious reading; triage can only end a case, not delay it.

Known limit: versions out of support are no longer re-analysed. A vulnerability published after their support ended and exploited right away won’t open a case for them.

If that check or the CISA KEV or ENISA EUVD import falls behind, CRA reports and the dashboard show Monitoring is delayed: until it recovers, no new case doesn’t mean nothing happened.

Known limit: the notice lives in the app. If boring.tools is down as a whole, nobody is alerted by email.

Deadlines

Step Due What it covers
Early warning 24 hours after detection The member states where the product is on the market
Notification 72 hours after detection The product, the vulnerability and the exploit, measures taken and measures users can take, how sensitive the information is
Final report 14 days after a fix is available Severity and impact, the attacker if known, the security update

Open CRA reports in the sidebar to see every open case with its next deadline; it turns red six hours before. On a case, owners and admins tick off each step with Mark as submitted and the reference the platform gives you, and set Fix available when a corrective measure is out — that starts the 14 days. Missed deadlines stay visible as overdue; nothing closes on its own.

Report drafts

Each case comes with a draft for every submission, field by field as Art. 14(2) asks for it: the product and affected versions, the member states, the nature of the vulnerability and of the exploit, measures taken and measures users can take, the sensitivity of the information, and for the final report the description, the attacker and the security update.

The drafts are built from what boring.tools knows — the advisories, your triage statements, fixed versions, the exploitation listings and the member states you set for the project. Where something is missing, the draft says so instead of guessing. Owners and admins edit any field (edits are kept), copy single fields or the whole step, and paste them into the platform.

With AI triage switched on for the project, Pre-write with AI writes the free-text fields from the public advisory data only. Fields you edited are never overwritten, and the cost counts towards the monthly AI budget.

Triage decides whether you are affected

A case is about the product, so triage still matters:

  • Not affected on every affected component closes the case, with your triage reason recorded.
  • Affected (or fixed) confirms it.
  • Changing a decision back, or a new untriaged version, reopens a closed case.

If everything was already triaged as not affected before the vulnerability was known to be exploited, the case is recorded as closed and nobody is alarmed.

Every step, decision and email is logged in the case’s Activity, with who did it and when.

Email notifications

Owners and admins get an email

  • when a case opens,
  • six hours before each deadline, and
  • once a deadline has passed.

On Mondays they also get a short digest — open reporting cases, projects with newly published or exploited findings, and support periods ending within 90 days. It is only sent when one of those has something to show.

Each person can turn these emails off under Account → Email notifications.