CRA Clock

EU Cyber Resilience Act . Article 14 . Applies from 11 September 2026

The clock starts the moment you know.

If you make software or a connected product sold in the EU and one of its components is being actively exploited, you have 24 hours to send an early warning, 72 hours to notify, and 14 days after a fix is available to file the final report. CRA Clock watches every dependency so you find out first.

Free and open source, Apache-2.0. A GitHub Action that runs in your own CI.

Demo . early warning due in 24:00:00

Departures

Three deadlines. None of them wait.

TimeDepartureWhat it carriesCRA Clock
0HCLOCK STARTSYou become aware that a dependency you ship is actively exploited, for example when it lands in CISA's Known Exploited Vulnerabilities catalog.Opens an issue
24HEARLY WARNINGActively exploited, which product, which Member States.Draft pre-filled
72HNOTIFICATIONNature of the exploit, corrective and mitigating measures.Draft pre-filled
+14DFINAL REPORTWithin 14 days after a corrective or mitigating measure is available.VEX tracks state

Article 14 also covers severe incidents; CRA Clock handles actively exploited vulnerabilities in your dependencies.

Live board

Just arrived in the exploited catalog.

The newest entries in CISA's Known Exploited Vulnerabilities catalog, read live through this site and cached for up to six hours. If one of these is in something you ship to the EU, your clock may already be running.

AddedCVEVendor and productRansomware
Reading the catalog...

Source: CISA KEV catalog. CRA Clock does not add, rank or interpret these entries.

Runs in your browser

Would your clock be running right now?

Drop any of the 12 lockfile formats CRA Clock reads: package-lock.json, npm-shrinkwrap.json, yarn.lock, pnpm-lock.yaml, requirements.txt, poetry.lock, Pipfile.lock, go.mod, Cargo.lock, Gemfile.lock, composer.lock or gradle.lockfile. Renamed files are recognised by their content.

Your lockfile never leaves your browser. Only package names and versions are sent to OSV.dev, and only CVE ids to FIRST. Privacy

How it works

One Action. Every push.
Every six hours.

1

SBOM

Knows what you ship

Reads 12 lockfile formats across npm, PyPI, Maven (Gradle), Go, Cargo, RubyGems and Packagist, and writes a CycloneDX 1.6 SBOM, a machine-readable SBOM format the CRA accepts.

2

Exploited, not just vulnerable

Signal, not noise

Every component is checked against OSV, then CISA's KEV catalog and FIRST's EPSS. Only evidence of exploitation starts the clock; high EPSS gets a warning. A failed lookup is flagged for manual review, never quietly passed.

3

Article 14

The clock and the paperwork

One issue per actively exploited vulnerability with the 24h and 72h deadlines, the fix version, and pre-filled early warning and notification drafts. The clock never resets on re-runs.

4

VEX

A record of triage

A CycloneDX VEX file marks each vulnerability in triage, with KEV and EPSS evidence attached, ready to share with customers and authorities.

What lands in your repo

An issue with the clock.
An SBOM you can hand over.

acme/router / Issues / #128

CRA Art. 14: actively exploited CVE-2021-44228 in org.apache.logging.log4j:log4j-core 2.14.1

Opencra-clocksecurityopened by github-actions

Componentlog4j-core 2.14.1
EvidenceCISA KEV, added 2021-12-10, known ransomware use
EPSS94.4% (percentile 100)
Fixed in2.15.0, 2.12.2, 2.3.1

CRA Article 14 clock

  • Early warningdue in 21h 14m
  • Vulnerability notificationdue in 69h 14m
  • Final report14 days after a fix is available

Draft: 24 hour early warning

Draft: 72 hour notification

Illustration of an issue CRA Clock opens. Figures shown are examples.
cra-clock/sbom.cdx.json
{
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "metadata": { "component": { "name": "Acme Router", "version": "v4.2.0" } },
  "components": [
    {
      "type": "library",
      "name": "org.apache.logging.log4j:log4j-core",
      "version": "2.14.1",
      "purl": "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1",
      "properties": [{ "name": "cra-clock:files", "value": "gradle.lockfile" }]
    }
  ]
}
Also written: vex.cdx.json and report.md, the job summary.

Install

Ninety seconds to install.

Add this workflow. It runs on every push to main and every six hours, because the KEV catalog changes daily.

.github/workflows/cra-clock.yml

name: cra-clock
on:
  push: { branches: [main] }
  schedule: [{ cron: '17 */6 * * *' }]
permissions: { contents: read, issues: write }
jobs:
  clock:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v5
        with: { persist-credentials: false }
      - uses: GautamTalksDev/cra-clock@v1
        with: { product-name: Acme Router }

Pin by commit SHA

For the strongest supply chain guarantee, pin the full commit SHA of a release instead of the tag, and let Dependabot bump it:

- uses: GautamTalksDev/cra-clock@<full-40-character-commit-sha> # v1.0.0

Pull requests from forks

Fork pull requests get a read-only token, so issues cannot be opened. CRA Clock then falls back to the job summary with a note. To keep runs clean, set open-issues: false on pull_request events.

- uses: GautamTalksDev/cra-clock@v1
  with:
    open-issues: ${{ github.event_name != 'pull_request' }}

Fare

Free

Free and open source (Apache-2.0). A hosted dashboard may come later.

Primary sources

CRA Clock prepares drafts and evidence. It is not legal advice and does not submit anything for you. Article 14 applies to manufacturers of products with digital elements made available on the EU market, and covers both actively exploited vulnerabilities and severe incidents; CRA Clock handles actively exploited vulnerabilities in your dependencies. Check whether your product is in scope. Exploitation evidence comes from the CISA KEV catalog, which is one reliable source among several; if you learn of exploitation another way, your clock started then.