Reporting Desk · CRA vulnerability reporting for manufacturers

Never miss a CRA reporting deadline.

The BitHive Reporting Desk watches the components in your products for actively exploited vulnerabilities, alerts two named people, runs the 24-hour, 72-hour and 14-day clocks, and prepares the reports you submit to ENISA. Hosted in Germany.

Request early access

Book a call

A reporting case in the Reporting Desk: Fleet Service, CVE-2023-44487, early warning due in 23 hours, two contacts alerted, one button to acknowledge.

Fleet Service

CVE-2023-44487 · HTTP/2 Rapid Reset

Actively exploited

Early warning due in 23 hNotification in 71 h · final report 14 days after the fix

  • Sources: CISA KEV and ENISA EUVD
  • Component: org.eclipse.jetty:jetty-http2-common 9.4.20
  • Alerted Erika Mustermann, escalating to Max Mustermann

What the Reporting Desk does today

  • Checked against CISA KEV and ENISA EUVD every hour
  • Version matching checked against the feeds’ own version lists: 57,283 comparisons, no disagreement
  • Data stored in Germany with a German hosting provider
  • You stay in control: we prepare, you submit

One product, one obligation, end to end.

From the bill of materials your pipeline uploads to the report text you paste into ENISA’s platform: the Reporting Desk covers the whole path, and shows you what it does not cover.

Alerts that reach a person.

Two named people per account, escalation if nobody reacts, acknowledgement straight from the e-mail.

Deadlines you cannot lose.

Every case runs the 24-hour, 72-hour and 14-day clocks, with a complete audit trail.

Reports ready when you are.

Guided forms for the early warning, the notification and the final report. You submit on ENISA’s platform.

See how it works

Built on open standards and public data.

No proprietary formats, no private feeds: what the Reporting Desk reads, you can read too.

CycloneDX
One of the two bill-of-materials formats we accept, as JSON, from your build pipeline.
SPDX
The second format we accept, also as JSON, so you keep the generator you already use.
CISA KEV
The catalogue of known exploited vulnerabilities, read every hour to decide when a clock starts.
ENISA EUVD
The European vulnerability database’s exploited list, read every hour as the second source.
OSV
The advisory data your components are matched against, per ecosystem, mirrored in Germany.

Early access

We are setting up accounts one at a time.

Self-service sign-up opens with production. Until then we set your account up by hand, with your own bill of materials, and walk the first case through with you.

Request early access

Book a call

BitHive also builds software for others.

Development, cloud and DevOps, security and compliance: the work this product grew out of.

What we do for clients