CRA duty records
CRA duty records: a product file before an Article 14 incident
Keep the role, checklist, open gaps, and Article 14 clocks before you must report. You still file on ENISA. The app does not submit the notification. Not legal advice.
CRALedger on the App Store: apps.shopify.com/craledger-duty-records. Article 14 reporting starts 11 September 2026. Main CRA cybersecurity requirements apply 11 December 2027. Confirm the latest pricing on the listing.
Different file: staff access audit · EUDR lot registry · EU right-to-repair records.
Install, record the product role, keep the Article 14 file
The path on this page is a CRA duty record you can retrieve before an incident — not an ENISA submission.
- Install CRALedger Duty Records from the App Store.
- Record the product role and checklist, and flag open gaps.
- Track Article 14 clocks. Prepare encrypted SRP drafts on plans that include that step.
- Export the audit pack when you need proof. File the notification on ENISA’s platform, not in the app.
The app stores duty records you enter. It does not file ENISA notifications or decide your role. This page is not legal advice.
Demo
Short walkthrough of the app flow. Then follow the start path below.
Prepare the file before the clock starts - file on ENISA, not in the app
| Record | Ecommerce consequence |
|---|---|
| Article 14 from 11 Sep 2026 | Report actively exploited vulnerabilities / severe incidents via SRP |
| Main CRA duties from 11 Dec 2027 | Essential cybersecurity requirements - later slice |
| ENISA Single Reporting Platform | Where the notification is actually submitted |
| Catalog duty file (this page) | SKU → role → checklist → gaps → clocks → draft pack |
Do not wait until 2027 to invent a product file if you already place products with digital elements on the Union market. Do not mix with EUDR lot registries or staff access audits.
Suggested path:
- Install CRALedger Duty Records.
- Record product role; run checklist; flag open gaps.
- Track Article 14 deadlines; prepare encrypted SRP drafts on plans that include those steps.
- Export record packs / audit evidence. Submit notifications on ENISA’s platform — not inside the catalog app.
The app does not file ENISA notifications.
Start path: duty file, not an ENISA login
- Open the CRALedger Duty Records listing (
apps.shopify.com/craledger-duty-records) and install it on the store that sells products with digital elements. - Record the product role and run the checklist. Flag open record gaps.
- Track Article 14 deadlines and prepare encrypted ENISA SRP drafts on the plans that include those steps.
- Export record packs and chronological audit evidence. When you must notify, submit on ENISA’s Single Reporting Platform — not inside the catalog app.
The app stores and drafts records you enter. It does not submit a notification to ENISA.
What the duty file holds vs what you file
| Record | Ecommerce consequence |
|---|---|
| Article 14 from 11 September 2026 | Report actively exploited vulnerabilities and severe incidents via the SRP |
| Main CRA duties from 11 December 2027 | Essential cybersecurity requirements — a later slice, not this page’s only job |
| ENISA Single Reporting Platform | Where the notification is actually submitted |
| Catalog duty file (this page) | SKU → role → checklist → gaps → clocks → draft pack you already prepared |
Example mapping you store against a product (paraphrase, not a filing form):
product / SKU
role (manufacturer / other)
duty checklist
open gaps
Art.14 clocks (early warning / follow-up / final)
SRP draft pack (encrypted)
audit export
What this page is not
- Not an ENISA filing tool, CSIRT portal, or CE-marking factory.
- Not legal advice, a role determination, or a compliance certification.
- Not an EUDR lot registry. That job is DDS reference numbers on supplier lots.
- Not a staff access audit. That path is permission drift after the last review.
When do Cyber Resilience Act Article 14 reporting duties apply?
Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents that affect product security from 11 September 2026. Notifications go through ENISA’s Single Reporting Platform to ENISA and the coordinating CSIRT. The CRA’s main cybersecurity requirements apply later, from 11 December 2027. This page is not legal advice. Confirm Regulation (EU) 2024/2847 and ENISA’s SRP pages.
Does keeping duty records mean I filed an ENISA notification?
No. Filing is a separate act on the Single Reporting Platform. A duty-records app can track roles, checklists, open gaps, Article 14 deadlines, and draft encrypted SRP packs. It does not submit the notification, obtain a case number, or replace ENISA’s platform.
What belongs in the product duty file before an incident?
Product role (manufacturer vs other actors), the checklist of duties that role carries, open record gaps, and the Article 14 clocks you will need if you become aware of active exploitation or a severe incident (early warning, follow-up, final report). Chronological audit evidence is how you retrieve that later. Confirm the live articles and Commission guidance, not this page.
Do Article 14 duties apply only after 11 December 2027?
No. Reporting is the early slice. Essential cybersecurity requirements, CE marking, and the rest of the CRA’s main obligations apply from 11 December 2027. Do not wait until 2027 to invent a product file if you already place products with digital elements on the Union market.
Is this the same as an EUDR lot registry or a staff access audit?
No. EUDR stores supplier-lot DDS reference numbers for deforestation-relevant commodities. An access audit scores staff and installed-app scopes. CRA duty records are product-with-digital-elements obligations and incident/vulnerability reporting. Do not mix those files.
Does an app make the catalog CRA compliant?
No. Whether you are a manufacturer, whether a SKU is a product with digital elements, and whether a notification was validly submitted are legal facts. A listing can store roles, gaps, deadlines, and draft packs. It does not file, decide your role, or guarantee compliance. Not legal advice.
Where do I keep CRA duty records and ENISA drafts?
Use a product-role checklist with gap review, Article 14 deadline tracking, and encrypted ENISA SRP drafts you can export. CRALedger Duty Records is the App Store listing this site already uses for that job. Open the listing, install, record roles and gaps, then keep the audit pack. You still file on ENISA’s platform.
Install CRALedger Duty Records, record product roles and gaps, track Article 14 clocks, then keep the audit pack ready for ENISA filing.
Related pages
- CRALedger Duty Records — live App Store listing
- EUDR DDS lot registry — commodity lots, not CRA incidents
- EU right-to-repair proof records
- Prop 65 2028 product-page warning — California short-form, not CRA incidents
- Staff permission drift access audit
- Shopify apps hub
- Tools
Not legal advice. Not a compliance guarantee. Not an ENISA filing. Confirm Regulation (EU) 2024/2847 before you treat a product as in or out of scope. The app stores duty records you enter; you file on the SRP. Confirm the latest pricing on the App Store.