Compliance tool
Is one of your dependencies a known exploited vulnerability?
Free instant check against CISA's live KEV catalog, plus a free EU CRA Article 14 report-field generator. No account, no signup.
Frequently asked
What is EU CRA Article 14?
The EU Cyber Resilience Act requires manufacturers of products with digital elements sold into the EU to report actively exploited vulnerabilities to ENISA: an early warning within 24 hours of becoming aware, a follow-up notification within 72 hours, and a final report within 14 days.
What does the free check do?
Paste a comma-separated list of your dependencies and it's checked live against CISA's public Known Exploited Vulnerabilities (KEV) catalog — the same feed used to decide whether something is a known, actively-exploited risk right now.
What does the report generator do?
If you already know you have a reportable vulnerability — from your own scanning, a vendor advisory, or a KEV match above — it produces the exact fields an ENISA early-warning report needs, with the 24h/72h/14-day clock computed from when you say you became aware. It's a drafting aid, not legal advice.
What does the $19/mo subscription add?
Daily monitoring instead of a one-time check: your dependency list is watched against CISA's KEV catalog every day, and you're alerted the moment a new match appears with the reporting clock already started.