Blog
The Cyber Resilience Act, and what we’re building against it
How the Article 14 reporting duty actually works, and the specific decisions behind how Declara reports, triages and files it. Every claim here carries the article it rests on.
Latest
Why your final CRA report isn't due 14 days after you find the bug
The Article 14 final-report clock never starts at awareness. It starts at a fix, or at a submission — and those two rules produce different deadlines.
Is your SaaS even in scope for the CRA?
"SaaS is exempt" is the most common CRA misconception, and it's only half true: a pure hosted service is out of scope, but the product it's part of usually isn't.
KEV match ≠ reportable incident: how we tier alerts so you don't cry wolf
A KEV listing, a high EPSS score and a mid-severity CVE are not the same signal. Declara's three-tier system decides what interrupts your day and what waits for the weekly digest.
You're outside the EU. Which CSIRT do you actually report to?
Article 14(7) picks your reporting authority through a four-step cascade when you have no EU establishment — and picking the wrong one can void a notification.
Why we made "suspected unlawful" a three-state field, not a checkbox
The SRP asks whether an incident is suspected to be caused by unlawful or malicious acts. Forcing a yes/no answer at hour six of a 24-hour clock forces a guess.
We don't scan your code, and here's why that's the right call
Declara reads the SBOM you already generate instead of scanning your repositories — because reporting and scanning are different jobs with different liabilities.