CRA Incident Reporting Clock & Evidence Pack
Track an owner-confirmed CRA reporting workflow through its 24-hour, 72-hour, and final-report evidence stages without deciding reportability.
What problem does CRA Incident Reporting Clock & Evidence Pack solve?
A product-security event can enter a time-sensitive reporting workflow while the awareness timestamp, product version, stage deadlines, evidence owner, revisions, and submission receipts remain scattered.
Use it to
- Start a CRA clock from an owner-approved awareness time
- Check early-warning and full-notification deadlines
- Preserve submission receipts and stage history
- Prepare a final-report evidence handoff
What it returns
- Case and reporting-stage evidence ledger
- Deadline and receipt findings
- JSON authorized-submission review gate
- Product-security owner review memo
A representative input and result
Access and approval boundaries
- Read access to one user-supplied local JSON evidence file.
- Write access only to the selected local output directory.
- No browser, network, credential, account, environment-variable, or external-action permission is required.
Known limitations
- The package does not decide whether the CRA applies or whether an occurrence is legally reportable.
- The user must supply the authoritative awareness time, final-report due time, product facts, and owner determination.
- It does not authenticate to or submit information through the Single Reporting Platform, ENISA, or a CSIRT.
Questions
Does it connect to a live account?
No. Version 1 reviews documented normalized local evidence only.
Does it take the external action?
No. It never submits, revokes, publishes, contacts, pays, or changes an external system.
What files does it create?
A findings CSV, evidence ledger CSV, summary JSON, and owner-review memo.
How does malformed input behave?
Missing identifiers, duplicate identifiers, bad timestamps, and invalid numbers fail before a ready result is produced.
Does a ready gate prove compliance or legal sufficiency?
No. It means the supplied records have no automated finding and are ready for the named owner or qualified reviewer.
Can the output be audited?
Yes. Every finding includes a stable code, record identifier, message, and source dataset.
CRA Incident Reporting Clock & Evidence Pack keeps proof and approval boundaries visible.
The listing includes the tested package, realistic samples, declared permissions, and known limitations.
Get CRA Incident Reporting Clock & Evidence Pack on Agensi