The EU Cyber Resilience Act reporting clock started on 11 September 2026 — 24 hours, 72 hours, 14 days, to ENISA and your coordinating CSIRT. Paste your file. Everything below runs in this tab; nothing is uploaded.
Checked one file. Now do the repository. The VS Code extension sweeps every Markdown file in the workspace at once, works out which checks are answered nowhere rather than merely missing from one file, and writes a single dated readiness report you can hand to an auditor.
Get the full version — $29$29 once · one licence key per person or team seat · 7-day full refund. One hour of EU product-compliance consulting runs $150-250.
A document linter, not legal advice and not a conformity assessment. Regulation (EU) 2024/2847, Articles 13, 14 and 16; Annex I Part II; Annex II. More tools: getreadystack.com
This page is the working piece. The full pack has everything below.
Reads your SECURITY.md against the EU Cyber Resilience Act reporting clock that started on 11 September 2026 — 24 hours, 72 hours, 14 days, to ENISA and your coordinating CSIRT.
One hour of EU product-compliance consulting runs $150-250, and a first documentation review is rarely one hour.
Buy the full version — $29It reads a Markdown file — SECURITY.md, a coordinated disclosure policy, an incident runbook — and names every line that will not survive EU Cyber Resilience Act Article 14. Eighteen rules cover the 24-hour early warning, the 72-hour notification, the 14-day final report, the recipients, the two triggers, and the supporting facts an auditor asks for. Each finding carries the article it comes from and one replacement line.
Maintainers and compliance leads at vendors placing software on the EU market, who own the security documents. It is written for the person who will be woken at 3am by an actively exploited vulnerability and needs the runbook to say who to notify, by when, and through which platform. Open-source stewards carry a lighter duty under Article 24; the rules here flag the manufacturer path.
Because they get the two questions wrong that matter most. General assistants still quote 11 December 2027 as the reporting start date — that is when the remaining obligations apply, while reporting has applied since 11 September 2026. They also reuse the GDPR Article 33 runbook, which has a similar 72-hour number but a different recipient and a different trigger. This linter checks your actual file for both mistakes.
Checking the file you have open is free forever, for personal or commercial use, with the complete rule set and no limits. The licence widens the scope: it sweeps every Markdown file in the workspace at once, reports which checks are answered nowhere in the repository, and writes one dated readiness report. The free scope finishes the job of fixing one document.
One hour of EU product-compliance consulting runs $150-250, and reviewing a security policy against Articles 13, 14 and 16 is rarely a single hour. The licence is $29 once, with a 7-day full refund. The linter does not replace counsel on scope or product classification; it removes the mechanical errors before anyone bills you to find them.
One question, answered by the person who built it. Your email only if you want the answer sent.