Observed arrival · 2026-09-09
ExploitClock turns exploited vulnerabilities into a compliance countdown
A CRA Article 14 reporting tool that watches software inventories for exploited vulnerabilities and helps prepare the required notifications.
Field notes
The service takes CycloneDX or SPDX software inventories through a UI, API, GitHub Action or Dependency-Track import, then checks components against OSV, CISA KEV, ENISA EUVD and FIRST EPSS. The page says checks run every 15 minutes and that teams separately record detection and awareness before confirming impact. It advertises hash-chained JSON, RFC 3161 receipts, CSAF 2.0 output and pricing from €79 per month for one product line.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue