compliance-ownerauditorP0Updated
Was this page helpful?
This page reflects our reading of Cyber Resilience Act, Article 14 and related guidance as of . It is not legal advice. Review process.
Declara automates the mechanical parts of Article 14 compliance. It doesn't remove the judgment calls — it makes them visible enough to make correctly.
| Area | Declara does | You remain responsible for |
|---|---|---|
| Deadline tracking | Computes 24h/72h/14d/1mo clocks from the moment you record awareness | Recording when you actually became aware — the clock starts there, not at upload |
| Report drafting | Assembles the SRP packet fields from your data | Filing it — Declara does not submit to the SRP; there is no SRP API today |
| Scope/triage | Surfaces the 4 fixed triage questions | Answering them correctly for your product and threat |
| Vulnerability matching | Tier A/B/C classification against NVD/OSV/GHSA/KEV/EPSS | Confirming exploitability in your context — Tier is not a legal determination |
| VEX | Suppresses matches you've already assessed as not-affected/fixed | Issuing accurate VEX statements in the first place |
| Evidence | Produces a hash-chained, independently verifiable record | Deciding what else your auditor or regulator needs beyond that record |
| Legal interpretation | Surfaces regulation text and deadline math | All legal judgment calls — the underlying legal template content is explicitly unreviewed by counsel today |