Regulation (EU) 2024/2847, Art. 14 reporting — applies from 11 September 2026 Get your runbook
Pilot slot

Regulation (EU) 2024/2847 · Cyber Resilience Act

Your product just got exploited. EU law gives you 24 hours. What happens at hour one?

From 11 September 2026, every manufacturer of connected products sold in the EU must file an early warning with ENISA within 24 hours of becoming aware of an actively exploited vulnerability or severe incident — then a full notification at 72 hours, then a final report. Most companies will meet this regulation for the first time during an incident.

Your people's names, not "[RESPONSIBLE PERSON]" Price on the page No cookies, no tracking

The four stages

The law starts the clocks. The pack means you are not reading the regulation at 2 a.m.

Penalties for breaching the reporting duties run to €15,000,000 or 2.5% of worldwide turnover — figures from the regulation itself, not our marketing.

T+0

Awareness

Reliable evidence that a vulnerability is being exploited, or an incident that affects the security of the product. Your incident lead starts the log. The clock has started.

ART. 3 · ART. 14(1)
24h

Early warning

Whether malicious acts are suspected, and the member states where the product is available. No technical analysis is required: the 24-hour clock rewards speed, not completeness.

ART. 14(2)(a) · ENISA SRP
72h

Notification

General information on the product, the nature of the exploit or incident, and any corrective or mitigating measures taken or available to users.

ART. 14(2)(b) · 14(4)(b)
14d / 1 mo

Final report

Fourteen days after your fix is available (vulnerability), or one month after the notification (incident): description, severity, impact, root cause, measures.

ART. 14(2)(c) · 14(4)(c)

See the actual product

These are real pages from a real pack. Not a mock-up.

Generated by our engine for a fictional company, Acme Devices GmbH, then printed exactly as a buyer would receive it. Your company, products, member state and people replace theirs.

Sample pack page one: named roles table, ranked gap list and the vulnerability runbook
page 1 · sample
Sample pack page two: the six pre-filled notification drafts
page 2 · sample

What you are looking at

A watermarked PDF, licensed to the buyer by name, with the corpus version and generation date on every page.

  • Named roles: your incident lead, technical and legal contacts and deputy, printed into every step
  • Two runbooks, one per legal track, hour by hour
  • Six notification drafts pre-filled with your company and products, only the incident facts left blank
  • A ranked gap list from your answers: what to fix first, and why

Click either page to enlarge. The sample shows no gaps because the fictional company answered every question well; most real packs do not.

What the pack contains

Specific to your company. That is the whole point.

Generic CRA templates sell for €700 and hand you "[RESPONSIBLE PERSON]". This pack prints your incident lead's actual name into the runbook and your products into the ENISA drafts.

01

Your runbook, with names in it

Step-by-step for both legal tracks: who does what at hour 0, 24 and 72, with your actual incident lead, technical and legal contacts named.

Named roles
02

Notifications drafted in advance

Early warning, 72-hour notification, final report and the user notice, pre-filled with your company and products, with only the incident facts left to complete at 2 a.m.

6 drafts
03

Gap list, ranked

No monitoring means you become aware late and lose the clock before it starts. Your answers produce a ranked gap list: what to fix first, and why.

Ranked by what bites first
04

Evidence register and walkthrough agenda

The log, the drafts as sent and the timestamps, filed in one place. Plus a 15-minute walkthrough agenda so your people know the runbook exists before they need it.

Included
05

Dated, versioned, regenerated

Corpus version and generation date on every page; regenerated free when ENISA guidance changes. A stale runbook is a liability; yours stays current.

12 months
06

Honest limits, printed in the pack

Internal readiness documentation, not legal advice. Nothing is filed with ENISA or any CSIRT on your behalf. The reporting obligations remain yours, and the pack says so on its last page.

On the last page

What happens after you say yes

Five steps. Nothing owed until step three.

Request a slot

One email with your company, your products with digital elements, and your member state.

TODAY

Scoping reply

We confirm fit, price and what we need from you. If the pack is not right for you, we say so.

WITHIN 1 WORKING DAY

Order confirmed in writing

Pay by card via Stripe, or by bank transfer against an invoice. Nothing is owed before this step.

WHEN YOU SAY GO

Short structured questionnaire

Your people, products, monitoring and contacts. Answers become the runbook, drafts and gap list.

YOUR PACE

Pack delivered, then kept current

Watermarked PDF by email. Regenerated free for 12 months when the guidance moves.

BY EMAIL

Founding pilot

Two ways in, prices on the page

Onboarding a small founding cohort by email, one company at a time.

One-off

Readiness pack

€490
founding-cohort pricing
  • Company-specific runbook, both legal tracks
  • All six notification drafts, pre-filled
  • Ranked gap list with remediations
  • Regenerated free for 12 months
Request a slot by email Or pay by card now — €490

Kept current

Maintained

€990/yr
for teams that never want a stale runbook
  • Everything in the pack
  • Regenerated on every guidance change
  • Change alerts: what moved, and why
  • Dated version history
Request by email
Pilot guaranteeIf your pack doesn't surface at least three gaps specific to your company, you don't pay.
Two ways to payCard via Stripe's secure checkout, refunded in full if the pack does not surface three company-specific gaps; or invoice after scoping, with nothing owed until your order is confirmed in writing. This site stores no payment details.
A registered companyIncidentReady is a trading name of Harmony Future Holdings Limited, registered in Ireland, Company No. 802912.

The alternatives: generic €700 template packs, or a four-figure legal-review engagement over weeks, against penalties of up to €15,000,000 or 2.5% of worldwide turnover. Our solicitor's pre-launch review is ongoing; its wording lands on these pages the day it arrives. Market price comparisons are third-party figures as at August 2026 and are not quotations.

Questions buyers ask

Read this before requesting a slot

Stated here rather than in the small print, because a readiness product that overclaims is the one thing that would actually get a customer hurt.

Is this legal advice?
No. IncidentReady produces internal readiness documentation: runbooks, drafted notifications, an evidence register. The reporting obligations under Regulation (EU) 2024/2847 remain yours. Verify deadlines and content against the regulation and current ENISA guidance before relying on them in an incident.
Do you file the notifications with ENISA for us?
No. Nothing is filed with ENISA or any CSIRT on your behalf. The filing platform itself is free: ENISA provides the Single Reporting Platform and publishes how-to guidance. What we build is your readiness to use it inside 24 hours.
Do weekends and holidays count?
Yes. The clocks run from the moment you become aware, whatever day it is. A pack on a shelf does not help either, which is why it includes a 15-minute walkthrough agenda so your people know it exists.
What if the pack finds no gaps?
Then you don't pay: an invoice is cancelled, a card payment is refunded in full. The pilot guarantee is that your pack surfaces at least three gaps specific to your company. The sample on this page shows none because the fictional company answered every question well; most real companies do not.
What do I need to provide?
Your company name and main establishment (member state), your products with digital elements, whether you monitor for exploitation, and the names and contacts of your incident lead, technical contact, legal contact and a deputy. That is what the questionnaire asks; that is what gets printed.
What happens when ENISA guidance changes?
The pack is regenerated free for 12 months, with the corpus version and date on every page. The maintained tier adds change alerts saying what moved and why, and a dated version history.
Is the penalty figure real?
It is from Article 64 of the regulation: administrative fines of up to €15,000,000 or 2.5% of worldwide annual turnover, whichever is higher. The exact band that applies to a reporting failure is a legal determination, which the pack flags for legal review rather than asserting.
Who is behind IncidentReady?
IncidentReady is a trading name of Harmony Future Holdings Limited, a company registered in Ireland (Company No. 802912), Dublin. Contact: hello@incidentready.eu. This site sets no cookies and runs no tracking.

Who you are dealing with

Built in Dublin by a registered Irish company, sold at a price you can see.

IncidentReady is one of a family of readiness products from Harmony Future Holdings Limited. Each one turns a regulation with a clock into a company-specific document, generated from your answers and honest about what it cannot do. No discovery call, no custom quote; card payments are taken by Stripe, and this site stores no payment details.

Trading nameIncidentReady
CompanyHarmony Future Holdings Limited
RegisteredIreland · No. 802912
LocationDublin, Ireland
Contacthello@incidentready.eu
Trackingnone · no cookies