An actively-exploited vulnerability or a severe incident starts a fixed, unforgiving reporting clock — 24 hours to an early warning, 72 hours to notification. 24·72 makes the call that starts it, runs every deadline, and drafts each report. Built for OT/ICS manufacturers.
A plain-English tour written for someone who has never read a word of the regulation: what the CRA is, whether it applies to you, what Article 14 actually demands, and the one judgment call almost everyone gets wrong. It comes with a worked example — a German gateway manufacturer on the afternoon two customers call — that you can click through end to end. Then swap in your own product.
Final report due 14 days after a corrective or mitigating measure is available.
Final report due 1 month after the 72-hour notification.
The call OT manufacturers get wrong: a vulnerability you discover and patch is ordinary vulnerability handling — not an Article 14 report. The clock starts only on active exploitation, or a severe incident impacting the product. 24·72 walks that distinction explicitly, and logs the decision either way.
Under a signed Article 14 mandate, 24·72 assembles each report and submits it through the Single Reporting Platform on your behalf. Not autopilot: nothing is transmitted until your reporting owner signs off, and the manufacturer remains the responsible party under Article 14.
Signed mandate. A standing authorisation to assemble and submit Article 14 reports.
Human sign-off gate. Your reporting owner approves every submission — it cannot be skipped.
Filed once. One submission reaches the CSIRT-coordinator and ENISA. You hold the receipt.
Reporting obligations carry administrative fines. The deadlines run from awareness — not from triage, not from a fix.
A live workbench: triage the trigger, run the 24h / 72h / final deadlines, draft every report, and keep the auditable submission log.
Launch 24·72 →