CRA 24/72/14 Reporting Lint (Article 14)
On 11 September 2026 the EU Cyber Resilience Act's reporting obligation started applying — including to products already on the market. From that date, a manufacturer who becomes aware of an actively exploited vulnerability or a severe incident owes three filings on a clock measured in hours: an early warning within 24 hours, a notification within 72 hours, and a final report within 14 days of a corrective measure being available. They go to ENISA and to the CSIRT designated as coordinator for your main establishment, through the single reporting platform. Most
What it checks — 18 rules, offline
Every finding carries the article it comes from and one concrete line to write instead. Nothing is sent anywhere: the rule table ships inside the extension and the whole run happens in your editor. Use it
That is the free scope, and it is the whole rule set — no watermark, no trial counter, no withheld finding. The full version widens the scope: it sweeps every Markdown file in the workspace in one pass, works out which checks are answered nowhere in the repository rather than merely missing from one file, and writes a single dated Full workspace sweep and report: free for 7 days from your first sweep, then a licence key. Settings
Honest limitsThis is a linter for a document, not a legal opinion and not a conformity assessment. It tells you that your runbook never names a CSIRT; it cannot tell you whether your product is in scope, which class it falls into, or whether a given vulnerability is being actively exploited. Article 14 also allows a one-month final report for severe incidents, and open-source stewards carry a lighter duty under Article 24 — the rules here flag the manufacturer path. Regulation (EU) 2024/2847, Articles 13, 14 and 16; Annex I Part II; Annex II. Other tools from the same workshop: https://getreadystack.com |

