compliance-ownerauditorP0Updated
Was this page helpful?

This page reflects our reading of Cyber Resilience Act, Article 14 and related guidance as of . It is not legal advice. Review process.

Declara automates the mechanical parts of Article 14 compliance. It doesn't remove the judgment calls — it makes them visible enough to make correctly.

AreaDeclara doesYou remain responsible for
Deadline trackingComputes 24h/72h/14d/1mo clocks from the moment you record awarenessRecording when you actually became aware — the clock starts there, not at upload
Report draftingAssembles the SRP packet fields from your dataFiling it — Declara does not submit to the SRP; there is no SRP API today
Scope/triageSurfaces the 4 fixed triage questionsAnswering them correctly for your product and threat
Vulnerability matchingTier A/B/C classification against NVD/OSV/GHSA/KEV/EPSSConfirming exploitability in your context — Tier is not a legal determination
VEXSuppresses matches you've already assessed as not-affected/fixedIssuing accurate VEX statements in the first place
EvidenceProduces a hash-chained, independently verifiable recordDeciding what else your auditor or regulator needs beyond that record
Legal interpretationSurfaces regulation text and deadline mathAll legal judgment calls — the underlying legal template content is explicitly unreviewed by counsel today