Reporting Desk · CRA vulnerability reporting for manufacturers

Never miss a CRA reporting deadline.

The BitHive Reporting Desk watches the components in your products for actively exploited vulnerabilities, alerts two named people, tracks the Article 14 deadlines and prepares the reports you submit to ENISA. Hosted in Germany.

Request early access

Book a call

A reporting case in the Reporting Desk: Fleet Service, CVE-2023-44487, early warning due in 23 hours, two contacts alerted, one button to acknowledge.

Fleet Service

CVE-2023-44487 · HTTP/2 Rapid Reset

Actively exploited

Early warning due in 23 hNotification in 71 h · final report 14 days after a corrective or mitigating measure is available

  • Sources: CISA KEV and ENISA EUVD
  • Component: org.eclipse.jetty:jetty-http2-common 9.4.20
  • Alerted Erika Mustermann, escalating to Max Mustermann

What the Reporting Desk does today

  • Checked against CISA KEV and ENISA EUVD every hour
  • Version matching checked against the feeds’ own version lists: 57,283 comparisons, no disagreement
  • Data stored in Germany with a German hosting provider
  • You stay in control: we prepare, you submit

One product, one obligation, end to end.

From the bill of materials your pipeline uploads to the report text you paste into ENISA’s platform: the Reporting Desk covers the whole path, and shows you what it does not cover.

Alerts that reach a person.

Two named people per account, escalation if nobody reacts, acknowledgement straight from the e-mail.

Deadlines you cannot lose.

Every case tracks the Article 14 deadlines (24 hours, 72 hours, and the final report 14 days after a corrective or mitigating measure is available), with a complete audit trail.

Reports ready when you are.

Guided forms for the early warning, the notification and the final report. You submit on ENISA’s platform.

See how it works

Built on open standards and public data.

No proprietary formats, no private feeds: what the Reporting Desk reads, you can read too.

CycloneDX
One of the two bill-of-materials formats we accept, as JSON, from your build pipeline.
SPDX
The second format we accept, also as JSON, so you keep the generator you already use.
CISA KEV
The catalogue of known exploited vulnerabilities, read every hour to decide when a clock starts.
ENISA EUVD
The European vulnerability database’s exploited list, read every hour as the second source.
OSV
The advisory data your components are matched against, per ecosystem, mirrored in Germany.

Early access

We open accounts one at a time.

Self-service sign-up opens with production. Until then we open accounts one at a time.

Request early access

Book a call