Article 14 exposure check
Twenty minutes on your product line and what you ship into the EU. You get a one-page memo within 48 hours telling you where you stand. We do not pitch you on the call.
If you hold a CE mark for the EU, the Cyber Resilience Act adds a new duty on top of it, and the reporting part starts first. We build it into the quality system you already certify against, and run each case through the corrective action process your team already knows.
Verified 24 Jul 2026. Regulations change; we re-verify before every engagement.
Twenty minutes on your product line and what you ship into the EU. You get a one-page memo within 48 hours telling you where you stand. We do not pitch you on the call.
Founding rate for the first three clients, in exchange for a named reference.
The whole thing built into your QMS: charter, intake, triage, disclosure policy, advisory templates, and the evidence pack an auditor will ask for. Mapped to IEC 62443-4-1 Practices 6 and 7.
After a sprint, most clients keep the process running on a part-time retainer. That conversation happens inside the sprint, not before.
| 8D step (corrective action) | CRA obligation | Clock | 62443-4-1 | What gets produced |
|---|---|---|---|---|
| D0 Plan & intake | You learn a vulnerability is being exploited. The reporting duty starts (Art. 14(1)) | 24 h | P6 · DM-1 | Intake record; early-warning submission to the SRP; clock log opened |
| D1 Team | A named reporter and deputy who can act inside the window | standing | P6 · DM-1 | RACI, on-call rota, escalation path |
| D2 Describe | Vulnerability notification: nature, severity, affected products (Art. 14(2)(b)) | 72 h | P6 · DM-2/3 | Characterized defect: what, where, since when, exploitation status |
| D3 Contain | Interim measures users can apply now; users informed | ASAP | P6 · DM-4 | Mitigation advisory: workaround, configuration change, or restriction |
| D4 Root cause | Why it got in, and why nothing caught it | n/a | P6 · DM-3 | Systemic root-cause record, twice over |
| D5 Corrective action | A security update that addresses the verified cause | n/a | P7 · SUM | The fix, qualified for the fielded fleet |
| D6 Validate | Evidence the fix closes the path it claims to close | n/a | P7 · SUM | Regression run plus targeted re-test of the patched path |
| D7 Prevent recurrence | The process fix behind the product fix | n/a | P6 · DM-5/6 | Updated coding standard, new CI detection, amended threat model |
| D8 Close & recognize | Final report: description, severity, measures taken (Art. 14(2)(c)) | 14 d | P6 · DM-5 | Final report filed; reporter credited; the 8D record archived as audit evidence |
Not for this. The CRA brings its own CE requirement in Dec 2027, but the reporting duty lands more than a year earlier, on 11 Sep 2026. That one has no grandfathering.
In the corrective action process you already have. Article 14 gives you a new trigger and three deadlines. The containment, root cause, and verification work is the same work your team does on any customer complaint. We are not asking you to stand up a second system beside your QMS.
No. We are advisory only. You stay the manufacturer of record. We get you ready for whoever assesses you.
If you put it on the EU market under your own brand, you are the manufacturer for that product. And your customers will push the requirement down to you either way.
Product requirements are grandfathered to Dec 2027. Article 14 is not (Art. 69(3)).
Because scoping surprises are a process failure.
Matthew Macri built a CRA and IEC 62443 programme inside a BC industrial manufacturer, from nothing to a signed charter: intake, triage, disclosure, and the evidence trail behind them. He runs the process he sells. Currently completing ISA/IEC 62443 certification. Based in British Columbia, works in client time zones.
Twenty minutes, a straight read on where you stand, and a one-page memo within 48 hours. We do not pitch you on the call.
Prefer email. matt@firstarticle.ca. Include your product line and where it ships; you’ll get times within one business day.
Email instead