SaaS for manufacturer reporting teams

The reporting workspace for CRA Article 14.

Designed as one place for your team to prepare CRA vulnerability and incident reports, track the deadlines, and keep submission evidence. Your team retains every legal decision and submits in ENISA SRP.

Article 14 uses time-critical staged reporting. Check the current official sources.

What the product design covers

Everything a reporting team has to keep straight.

Article 14 reporting pulls in security, legal, engineering, and the person who files. The product is designed to keep that work in one attributable case record.

Deadline control

Case clocks are designed to anchor to factual awareness time, kept separate from the time a user records or declares that awareness. The governing source controls each limit.

Staged reports

Draft the early warning, notification, and final report as versions.

Decisions on record

The record model attributes who decided, the basis recorded, declared awareness, review, and human submission.

Audit evidence

A case history designed to preserve attributable decisions, report versions, and submission evidence for later review.

How the work moves

Prepare once, then keep each decision clear.

The workflow model follows the reporting path a manufacturer has to coordinate. The manufacturer owns the legal decision, and the authorised filer controls the external portal.

01

Prepare

Set up company, product, reporter, and routing details before you ever need them.

02

Decide

Your team decides whether it is reportable and records when you became aware.

03

Review

Draft each report stage, keep every revision, and get sign-off before anything leaves.

04

Hand off

Copy values across one at a time, submit in ENISA SRP, and record the outcome.

Where ActLume stops

The software organises the work. People make the call.

ActLume is designed around Article 14 facts, decisions, drafts, handoff, and evidence. Its product boundary excludes portal sign-in and filing on a customer's behalf.

Product scope keeps together

  • The facts and the decisions, clearly separated
  • Where each case stands, visible at a glance
  • Review before anything leaves the workspace
  • Submission evidence kept for later audit

Your team still decides

  • Whether an incident is reportable
  • When you became aware of it
  • Signing in with EU Login
  • Reviewing and submitting in ENISA SRP

Built for scrutiny

A security review can start here.

Production requirements use one conventional SaaS security baseline across both plan definitions.

Transport

Encrypted transit

Production policy requires encrypted transit and rejection of legacy TLS versions.

Isolation

Server-side tenant and role boundaries

Production policy requires tenant and role enforcement on the server.

Residency

Frankfurt primary-region policy

Production policy selects Frankfurt for primary customer-data resources and requires separate access and transfer disclosures.

Read the full security baseline See residency and transfers

Plans and pricing

One approved Core Team price.

The published commercial model is €499 per month or €4,990 per year for 10 named seats, with the intended Article 14 workflow scope described on this site.

Choose your starting point

Start with the question in front of you.

Read the legal overview, walk through the workflow, or check the security boundary. The blog covers practical reporting questions in more detail.

Next step

See where ActLume fits into your incident process.

Follow the six reporting steps