CRCRA Drill Kit

OFFLINE BROWSER WORKSPACE · SOURCE-CHECKED

Turn a 24-hour clock
into a rehearsed packet.

Prepare the people, facts, evidence, and handoffs behind CRA early warnings, 72-hour notifications, and event-based final reports.
Buy for $59Use the free reporting clockBuild a free stage brief
English · opens locally · JSON portability · print packet · no external data path
CRA-DRILL-001 · local session
FICTIONAL SEVERE INCIDENTExample connected device
68% READY
01
EARLY WARNING12 Sep · 09:00
24H
02
INCIDENT NOTIFICATION14 Sep · 09:00
72H
03
FINAL REPORTEnter submission time
EVENT
OwnerIncident lead
Evidence8 references
Data pathBrowser memory
01Detect

Preserve the awareness trigger and known uncertainty

02Escalate

Assign decision owners before the first window closes

03Prepare

Structure facts, measures, users, and markets

04Evidence

Retain approvals, references, and submitted material

WHY NOW

The reporting duty arrives before the rest of the CRA.

6 WORKFLOWS · 2 FICTIONAL DRILLS

Practice the operating system, not just the dates.

The ZIP contains a complete offline HTML app, source, tests, two fictional JSON cases, official source notes, quick start, change log, sales copy, and an internal-use commercial licence.
01

Offline drill room

Run locally in a current browser with no account, analytics, API, or hosted database.

02

Deadline engine

Calculate 24-hour and 72-hour milestones plus the correct event-based final-report date.

03

Preparation prompts

Structure early-warning, main-notification, and final-report facts without hiding uncertainty.

04

Evidence workspace

Capture owners, approvers, actions, evidence references, markets, and decision boundaries.

05

Portable packet

Export or import JSON and print a review-ready rehearsal packet.

06

Fictional drills

Start with severe-incident and exploited-vulnerability examples before using approved real data.

OFFICIAL-SOURCE BOUNDARY

A rehearsal packet is not an official notification.

This kit does not determine applicability, reportability, legal awareness, severity, exploitation, affected Member States, confidentiality, or exceptions. It never submits data.
Commission reporting guidance ↗ENISA Single Reporting Platform ↗

FAQ

Keep the legal and technical boundary visible.

Does the kit decide whether an occurrence is reportable?

No. Qualified teams must determine scope, awareness, exploitation, severity, affected products, markets, and applicable exceptions.

Does it submit to the CRA Single Reporting Platform?

No. The kit is deliberately offline and does not connect to ENISA, a CSIRT, or any external service.

How is the severe-incident final date calculated?

It is one calendar month after the actual 72-hour incident-notification submission. The app does not silently assume the due date was the submission date.

How is the vulnerability final date calculated?

It is no later than 14 days after a corrective or mitigating measure becomes available, so the app leaves it unfixed until that event is entered.

What does the licence cover?

One legal organisation may use and modify the kit for its own internal teams and products. Resale, redistribution, and competing hosted or downloadable products are not allowed.

LAUNCH EDITION

Rehearse the first 72 hours before they are real.

Offline app, source, deadline tests, fictional cases, JSON portability, print packet, source notes, quick start, and one-organisation internal-use licence.