Observed arrival · 2026-09-16
craclock, the EU vulnerability-reporting clock
A planned tool that records when a team learns a shipped product is being exploited, calculates EU CRA Article 14 deadlines, and prepares text for ENISA reporting.
Field notes
craclock centers its workflow on the moment a team becomes aware that a shipped product is being exploited, rather than the later act of completing a report. Its displayed sequence covers a 24-hour early warning, a 72-hour notification, and a final report 14 days after a fix. The site says ENISA's portal has no API, so the proposed output is a package users paste manually. The CLI and several automation features are presented as planned rather than verified current functionality.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue