Article 14 reporting starts 11 September 2026.See what you need in place

Start with a product

Create the products and releases you placed on the market, attach their SBOMs, then run monitoring, triage, reporting, and customer advisories from that inventory.

Open the dashboard

Free Basic plan, no credit card. See plans

The working loop

Inventory, monitor, decide, then tell people

Every later step reads from the same products and releases. You do not start with a scanner dump or a rebuild toolchain.

  1. Create products and releases

    A product is what the CRA holds you accountable for. Give it a name, a support period, and a risk class. Then list every firmware version you have placed on the market. That list is what an authority, and later an advisory, will be scoped against.

  2. Attach SBOMs

    Upload CycloneDX or SPDX per release, or have your pipeline push one on every build from GitHub Actions, GitLab CI, or any CI that can call the API. If the vendor document is missing or you do not fully trust it, derive an inventory from the firmware binary.

  3. Monitor SBOMs

    Scheduled rescans check every stored inventory against vulnerability intelligence. New high and critical findings go to your PSIRT inbox, never to your customers. KEV and EUVD overlay tells you when something you already shipped is being actively exploited.

  4. Triage discoveries and effects

    A scan is not a decision. For each finding, record whether the product is affected, not affected, or a false positive, with justification and history. That log is what assessors, Article 14 packets, and customer advisories all read from.

  5. Report, then publish advisories

    When a finding is actively exploited in a shipped release, stamp awareness and prepare the 24-hour, 72-hour, and 14-day packet to copy into ENISA SRP. Alloy does not submit. Separately, turn on your organisation's public security page and publish advisories scoped to the releases that are actually affected.

A public security page for your company

Published advisories are readable without a login at your organisation URL, branded with your logo. Customers see affected and not-affected releases, the recommended version, and the document history, as a page, CSAF JSON, and PDF.

The portal stays off until you enable it. Publishing and sending email are independent: you can publish without mailing, or mail without publishing.

How advisories work

Need to rebuild an affected release later?

Blueprints and the open-source provisioner reconstruct the environment that built a binary. That is the reproduce leg, after triage confirms impact, not where CRA operations start. Blueprints catalog