CRA · For CTOs and product security teams
CRA: from public signal to a documented assessment.
For manufacturers of software and connected devices within CRA scope: bring public signals together, prioritise review, assign owners and document actions in Awarely Monitor.
No credit card. Eligible new accounts receive 14 days of Pro; access returns to Free without an active subscription.
Monitor supports internal assessment and evidence preparation. Official reporting takes place separately through the SRP; Monitor does not submit notifications to ENISA or guarantee CRA compliance.
Four steps to try with one of your products
1. Identify relevant signals
NVD, CISA KEV, EUVD and GitHub Security Advisories are collected on a scheduled two-hour cycle. CVSS, EPSS from FIRST and KEV context help prioritise review. Check the last synchronisation on the Status page too.
2. Review the product and version
In Pro, import CycloneDX JSON, SPDX JSON, package.json or requirements.txt. The inventory accepts up to 1,000 entries. Matches are version-confirmed only where the data permits; product-level results need review. A declared version range does not prove the installed version.
3. Assign and document
Use assignments, statuses, notes and activity history for the CVE under review. Record product context, reasoning and sources consulted. Pro adds internal remediation SLAs and Jira/Linear ticket creation after configuration.
4. Prepare material for review
Export the CVE list as CSV/XLSX and audit records as JSON/CSV. Starter and Pro include a date-range Evidence Pack; Pro adds the Asset Exposure report. Review date coverage and separately complete the awareness timeline, reporting decision and evidence of SRP submission.
An assessment to try during your trial
Import one product’s inventory, select a relevant CVE and check the version and exploitation conditions. Assign the review to a colleague, add your conclusion in notes and export the available records. Use the result to evaluate whether Monitor fits your team’s process.
Choose a plan for the workflow you need to evaluate
Starter — €59/month: up to 5 users, statuses, notes, assignments, Critical-severity email, CSV/XLSX, audit and Evidence Pack within a 90-day window. Does not include Pro inventory or advanced integrations.
Pro — €199/month: up to 5 users, inventory/SBOM import, supported-severity alerts through email, Slack, Teams Workflows and signed outbound webhook, internal SLA, Jira/Linear, additional reports, 12-month retention and a CVE data API with 50,000 requests/month. Access depends on role and configuration; the Monitor API is not an SRP API.
Start with the actual product workflow
Create your account, accept the terms and privacy policy, then confirm your email when prompted. After sign-in, dashboard onboarding guides you through a watchlist, alerts and inviting a colleague. Inventory is in Settings → Assets. Enterprise OIDC SSO is assisted and requires separate setup.
What your own process needs to cover
- The two-hour cycle is a collection schedule, not a freshness or delivery guarantee. Public sources may publish late or incomplete information. Monitor does not detect every vulnerability or incident and does not replace telemetry, testing or customer reports.
- Inventory is a list of imported components, not a complete product release register or an SBOM generator or compliance validator. Matching does not establish exploitability in your product.
- An internal remediation SLA is not a statutory CRA reporting deadline. Collection and audit timestamps do not automatically establish the legal moment of awareness.
- Exports reflect available data and plan retention; they are not a complete CRA dossier or an SRP form. The platform also attempts a secondary S3 retention copy of audit events, without guaranteeing that every write reaches it.
CRA reference points for your team’s assessment
Article 14 applies to manufacturers from 11 September 2026, including older products within scope. The main CRA requirements and the specific obligations for open-source software stewards under Article 24(3) apply from 11 December 2027. SaaS is not automatically in scope: assess the definition of remote data processing. CRA Regulation
The CRA sets product obligations for manufacturers. NIS2 sets risk-management measures for in-scope entities, including supplier security. One organisation can fall under both. NIS2 supplier security · Monitor for NIS2
Reporting concerns actively exploited vulnerabilities and severe incidents affecting product security. A CVE, CVSS or EPSS score alone does not automatically trigger reporting. For third-party components, Commission FAQ §5.4 requires product context: a vulnerability that cannot be exploited in that product is not subject to this mandatory reporting. FAQ — European Commission
- 24 hours
- Early warning, without undue delay, from becoming aware.
- 72 hours
- Notification, without undue delay, from the same moment of awareness; not after the 24-hour stage.
- Final report
- Vulnerabilities: no later than 14 days after a corrective or mitigating measure becomes available. Severe incidents: one month after the 72-hour notification. The 14 days are not a general patching deadline.
European Commission: reporting obligations
The SRP has been operational since 11 September 2026. Checked on 13 September, the ENISA FAQ updated on 12 September states there is no submission API at launch: notifications must be submitted through the SRP interface. FAQ ENISA
Context and sources · checked 13 September 2026
Monitor supports internal assessment and evidence preparation. Official reporting takes place separately through the SRP; Monitor does not submit notifications to ENISA or guarantee CRA compliance.
Start your 14-day Pro trial