Skip to content
11 days until the Art. 14 reporting obligation (11 September 2026).
Documentation Support Risk class
00Where the signals come from

Your scanner finds the CVE. CRAnotify turns it into a case to qualify — not an email someone might read.

Keep Dependency-Track. Keep your SBOM pipeline. Keep Slack. CRAnotify hooks on at the end of them and turns what they find into a regulatory case with a deadline, a tamper-evident registry entry and a dossier. It replaces none of them.

A signal is never a filing. Everything that comes in becomes a case a person has to read, qualify and approve. CRAnotify never sends anything to an authority in your place: it prepares the filing, you file it on the ENISA single reporting platform with the notification already written.

01Three ways in

Three ways in. One case, one timeline, one dossier.

01

Give researchers one place to write

A security.txt and a public form per product mean the report lands in your registry with a date and a time on it, not in somebody's inbox. When it arrives by phone instead, you open the case by hand.

  • security.txt
  • Public reporting form, one per product
  • Manual case entry for everything else
02

Answer “which products is it in?” without a spreadsheet

Push CycloneDX or SPDX straight from the build, or connect Dependency-Track with a URL and an API token. Components and vulnerabilities sit next to the product, so by the time you write the notification the affected-products question is already answered.

  • CycloneDX
  • SPDX
  • Dependency-Track
03

A 24-hour deadline nobody opens is a missed deadline

The 24-hour early warning, the 72-hour notification and every escalation show up in Slack or Teams, or on an endpoint of yours through a webhook or the API. The countdown itself lives in the case: if a channel goes down, the deadline does not move.

  • Slack · Microsoft Teams
  • Webhook HTTP
  • API
03From signal to dossier

From a scanner alert to a dossier you can hand over.

The connections move the data. What counts as a reportable vulnerability, who signs it off and when it goes to the authority: you decide all three. What CRAnotify does is write down every step of that decision, in order, with its timestamp — the part you will need if somebody asks you, months later, why you did what you did.

  1. 1

    The signal arrives

  2. 2

    It lands as a case

  3. 3

    A person qualifies it and sets hour zero

  4. 4

    Decision, signed off

  5. 5

    Dossier ready, you file

Before 11 September 2026

Connect one source today and see what a real case looks like.