PortaRegulus
HOME
10 // INTEL · PRODUCT

From one deadline to the whole CRA.

CVD Portal started as the answer to a single reporting duty. It now runs the entire compliance lifecycle.

PortaRegulus Intel CRA · Product 24 Jul 2026

The Cyber Resilience Act has one deadline on the near horizon and a much larger one behind it. We built for the near one first, then extended the same platform to carry everything the regulation asks for after it. This is what one account now covers, and how it connects to the tools a team already runs.

Where it started

The first CRA obligation to bite is the reporting duty. From 11 September 2026, manufacturers have to report actively exploited vulnerabilities and severe incidents to ENISA and their national CSIRT inside the 24-hour and 72-hour windows of Article 14. That is a short fuse for a company with no security team on call.

CVD Portal was built to make that duty manageable. Every company gets a whitelabel coordinated disclosure portal on its own subdomain, where researchers submit reports through a structured intake form. Behind it sits the machinery that turns a raw report into a filing, with triage, deadline tracking against the Article 14 clock, RFC 9116 security.txt generation and validation, and CSAF export for machine-readable advisories. That product is live and doing its job at cvdportal.com, and the free tier covers it.

What the platform covers now

Reporting is the visible deadline. It is one obligation among many, and the rest come due when the full CRA applies on 11 December 2027. With intake solved, we extended the same infrastructure to carry the conformity work, all of it at cvdportal.com/cra with a free trial to start.

It fits the tools you already run

Compliance work does not live on an island. The platform connects to Jira and Confluence so evidence and tasks stay in sync with engineering, and pushes alerts into Slack and Teams so a new report or an approaching deadline lands where your team already looks. Webhooks and a REST API cover everything else you want to wire up.

AI across the whole lifecycle

AI runs through every stage, from suggesting a product classification, to drafting assessment answers and technical documentation, to triaging an incoming vulnerability report and proposing a severity. It works as a drafting partner that gets you to a reviewable first version quickly, with a person always making the final call.

For manufacturers and the people who advise them

The platform serves two audiences. If you are a manufacturer as the CRA defines one, it is your compliance system of record. If you are a consultancy or reseller, it is the workspace you run several clients through at once, with the same structure applied to each engagement.

It also keeps improving in the open. Paid-tier users can send suggestions straight through the in-product feedback, and that steer shapes what gets built next, so the tool keeps bending toward the way real teams work.

What this does not claim

No platform makes you compliant, and we do not sell presumption of conformity. The harmonised standards that would confer it are still working their way toward Official Journal citation. What the platform does is structure the work the regulation actually asks for and keep the evidence in one place, so the judgment calls that remain yours are made on top of a complete file.

The platform is live now. Start at cvdportal.com/cra for the compliance workspace, or at cvdportal.com for a disclosure portal first. It is the same platform either way.

One platform. Every CRA obligation.