CRA Reporting Clock Lint (EU 2024/2847)

Checks SECURITY.md against the EU Cyber Resilience Act clocks that went live 11 Sep 2026: 24h early warning, 72h notification, 14-day final report, 5-year support period, CVD policy, SBOM. Runs entirely in your browser — nothing is uploaded.

Same engine as the VS Code extension, byte for byte.

Get the complete version $29

This page is the working piece. The full pack has everything below.

Checks your SECURITY.md against the Cyber Resilience Act clocks that went live on 11 September 2026.

The human alternative is EU product-compliance counsel reading the same file by the billable hour; Art. 64(2) caps an Article 13 or 14 infringement at EUR 15,000,000 or 2.5% of total worldwide annual turnover, whichever is higher.

Buy the full version — $29

Questions people ask

What does CRA Reporting Clock Lint actually do?

It reads the SECURITY.md you have open and checks it against 17 rules drawn from Regulation (EU) 2024/2847. Each finding names the article or annex point and the deadline: 24 hours for the early warning, 72 hours for the notification, 14 days for the final report, five years for the support period. It reports; it does not file anything.

Who is this for?

Maintainers and product engineers who place software with digital elements on the EU market and own the repository's SECURITY.md. That includes commercial open-source vendors, SaaS teams shipping installable agents, and firmware teams. It is aimed at the person who has to answer a customer's CRA questionnaire, not at a compliance department.

Why not just use a free Markdown linter or a chat assistant?

A Markdown linter checks heading levels and link syntax. It has no article numbers, and it cannot tell that a published support end date of 2025-12-31 has already passed. This extension compares your file against dated obligations and against today's date, offline, with the clause number attached to every finding.

What is free and what needs a licence key?

Free covers one file completely: open a SECURITY.md, run the lint, read every missing or contradicted clause with its article number. The full version adds a different axis, not a bigger drip: a workspace-wide pass over every SECURITY.md, and a written, dated audit file containing the corrected clause-referenced text.

What would this cost done by a person?

The ordinary route is having EU product-compliance counsel read the policy by the billable hour, then repeating that each time the file changes. The statutory ceiling on the other side is Art. 64(2): EUR 15,000,000 or 2.5% of total worldwide annual turnover for an Article 13 or 14 infringement, whichever is higher.

Ask about this tool

One question, answered by the person who built it. Your email only if you want the answer sent.

Want the full version?
Enter your email and we send the download link.
ENDEJAESPT

Find a tool