Reporting Desk

Never miss a CRA reporting deadline.

The Reporting Desk watches the components in your products for actively exploited vulnerabilities, alerts two named people, runs the 24-hour, 72-hour and 14-day clocks, and prepares the reports you submit to ENISA. Hosted in Germany.

For manufacturers of products with digital elements sold in the EU.

Start free trial

Book a call

A reporting case in the Reporting Desk: Fleet Service, CVE-2023-44487, early warning due in 23 hours, two contacts alerted, one button to acknowledge.

Fleet Service

CVE-2023-44487 · HTTP/2 Rapid Reset

Actively exploited

Early warning due in 23 hNotification in 71 h · final report 14 days after the fix

  • Sources: CISA KEV and ENISA EUVD
  • Component: org.eclipse.jetty:jetty-http2-common 9.4.20
  • Alerted Erika Mustermann, escalating to Max Mustermann

The obligation

Since 11 September 2026, manufacturers must send ENISA an early warning within 24 hours of becoming aware of an actively exploited vulnerability in their products, including products already on the market. Weekends and holidays count.

Why a reporting desk

Security of the Reporting Desk

General information, not legal advice.

How it works.

  1. Upload your SBOMs

    Through the web interface or the API from any CI pipeline, in CycloneDX or SPDX JSON. We never see your source code.

  2. We watch every hour

    Components are matched against OSV advisories, and exploitation is checked against CISA KEV and ENISA EUVD.

  3. The right people are alerted

    E-mail and webhook to your two named contacts, with escalation if nobody acknowledges.

  4. The report is prepared

    Guided forms for each deadline, ready to copy into ENISA’s platform, with the submission recorded.

Coverage, stated honestly.

A tool that shows you a clean result for components it cannot judge is not telling you the truth. You always see what is covered.

Monitored today: npm, PyPI, Maven, Go and NuGet.

Debian and Alpine packages are shown as not monitored, with the reason, until release-aware matching is available: an advisory names one distribution release, and matching does not compare releases yet.

Why BitHive.

Accuracy you can check

The release gate runs on bills of materials from real open-source projects, and every version comparison is checked against the feeds’ own version lists: 57,283 comparisons in the five supported ecosystems, with no disagreement.

Built for the clock

Deadlines are stored with the case, the audit log is append-only in the database, and an alert that reaches nobody raises an alarm with us.

German hosting, no US cloud provider for your data

Your bills of materials, cases and reports stay in German data centres. E-mail is delivered by an EU provider, named in the data processing agreement.

No lock-in

Your uploaded bills of materials, case records and the audit log download as files whenever you want them.

Prices are public.

Priced per company, with product bundles, because CRA obligations attach to products.

Starter

€149 per month

Up to 3 products, fully covered.

Team

€449 per month

For a product portfolio and a team.

Portfolio

€990 per month

For manufacturers with many products.

Prices exclude VAT. Two months free with annual billing.

See all plans and prices

What it looks like

The application, in the language you read it in. These pictures are the demonstration data, not a customer’s.

A reporting case in the application: a red banner saying one early warning is overdue, the vulnerability CVE-2023-44487 on the product Device Bridge, the sources that list it as exploited, and a timeline from recorded to acknowledged.
A case: what happened, when, and what is still due.

Nothing in these pictures belongs to a customer: they are taken from our demonstration account, which is why the banner says so.

Questions.

Is this legal advice?

No. The Reporting Desk supports the technical process. Whether and how the CRA applies to your products is for you and your legal counsel to decide.

Who submits to ENISA?

You do, through your own EU Login on ENISA’s Single Reporting Platform. We never submit for you: we prepare the text and record when you submitted it.

Where is our data?

In data centres in Germany, operated by the German hosting provider STACKIT. E-mail notifications are delivered by Brevo, an e-mail provider in the EU. Details and safeguards are in our Data Processing Agreement.

What if we have no SBOM yet?

The documentation shows how to generate one in your build pipeline with established open-source tools, and how to upload it with one API call.

What happens at 3 a.m. on a Sunday?

The case opens and your first contact is alerted. If nobody acknowledges, the second contact is alerted. Acknowledging works straight from the e-mail, and the link works once.

See it on your own components.

Twenty minutes, your bill of materials, and an honest answer about what we would watch and what we would not.

Start free trial

Book a call