CRA Reporting Copilot / Support & FAQ

Support & FAQ

This product is a compliance-support tool, not legal advice. It does not determine, submit, or guarantee compliance with CRA (Regulation (EU) 2024/2847) reporting obligations. You (the manufacturer) remain responsible for all reporting decisions, submissions, and deadlines. Verify all outputs and consult a qualified professional.

Getting started

What does CRA Reporting Copilot do?

It helps teams that run incident response in Jira or Jira Service Management prepare EU Cyber Resilience Act (CRA) Article 14 reports and notifications. From a ticket, it helps identify cases that may be reportable, tracks each staged deadline from the correct start point, and generates draft reports and notifications for your team to review, export, and submit. It is a support tool — it does not file anything for you and does not decide borderline cases on your behalf.

Which products does it work with?

Jira and Jira Service Management (Cloud). It installs as an Atlassian Forge app.

How do I install it?

Install it from the Atlassian Marketplace like any Forge app. Your Jira site admin approves the requested permissions once, and the app appears in your project. No external account, API key, or connector setup is required.

What permissions does it request, and why so few?

Two, and only two: read access to Jira work data (read:jira-work) so it can read the issues and requests you point it at, and app storage (storage:app) so it can keep your register, logs, and drafts inside your Atlassian tenant. It requests no write access to your issues and no external network (egress) permission at all. The short permission list is deliberate — it is what lets the app run entirely on Atlassian.

Do I need to connect anything external — an API key, an LLM, a data feed?

No. There is nothing to connect. The app uses no large language model and no live external feed. Draft generation is template- and rule-based, and the Known Exploited Vulnerabilities (KEV) data ships inside the app as a snapshot (see below).

Data location and trust

Does my incident data leave my Atlassian tenant?

No. The app is built to the "Runs on Atlassian" model: it uses only Atlassian-hosted compute and storage and declares no external egress. Your issue data, drafts, register, and logs stay inside your tenant. The app has no developer-operated backend that processes your issue data.

Where are my drafts and register stored?

In Forge app storage, inside your Atlassian tenant. They are not copied to any external system.

Is there an audit trail?

Yes. Every reporting action — draft generated, edited, exported — is written to an append-only log (who, when, what, which version). The log is designed so entries are added, not altered.

Do you use AI / an LLM to write the reports?

No. Drafts are produced from reviewed templates and rules, not a language model. This keeps generation deterministic and keeps the app within the zero-egress design. (A future bring-your-own-key LLM mode may be considered separately; it is not part of this version.)

KEV snapshot

Where does the Known Exploited Vulnerabilities data come from, and is it live?

It is a bundled snapshot of the public KEV catalog, shipped inside the app — not a live external feed. This is what keeps the app egress-free. The snapshot's date is shown in the app so you always know how fresh it is.

How does the KEV snapshot get updated?

Through app updates. When we publish a new release, the bundled snapshot is refreshed, and you receive it the same way you receive any Forge app update. Because it is a snapshot, treat it as a point-in-time reference: for the very latest entries, cross-check the authoritative public source. We show the snapshot date precisely so its freshness is never overstated.

Reporting, deadlines, and responsibility

Which reports and notifications can it draft?

The full Article 14 set: the 24-hour early warning, the 72-hour notification, the final report, the notice to affected users, and — where a third-party component is involved — the notice to the upstream component maker.

How does it handle the deadlines?

Each stage counts down from its correct start point. The two final-report start points differ and the app keeps them distinct: for a vulnerability, the final report is tracked to 14 days after a corrective or mitigating measure is available; for a severe incident, to one month after the 72-hour notification is submitted — not one month after you became aware. You enter the start events; the app tracks the clocks and displays alerts as deadlines approach.

When does the clock start — how does the app know when we "became aware"?

It doesn't decide that for you. The point at which you "become aware" is a judgment that depends on official guidance, so the app asks you to confirm the awareness time and starts the count from what you enter. Cases near a boundary are flagged for human confirmation rather than resolved automatically.

Does the app submit the report to the authorities for me?

No. The app never files anything. You export the draft (PDF or JSON) and submit it yourself through the appropriate channel. This is by design: the app writes the draft, a person reviews and submits it.

Who is responsible for actually meeting the reporting obligation?

You are. CRA Reporting Copilot supports your process; it does not assume your legal obligation. Responsibility for whether, what, and when you report — and for notifying affected users — remains with your organization.

Who is responsible for notifying affected users?

You are. The app drafts the affected-user notice so you can send it promptly, but the duty to notify users sits with you as the manufacturer. (Note that where a manufacturer fails to inform users of an actively exploited vulnerability, the coordinating CSIRT may, if it judges it proportionate and necessary, inform users directly — another reason not to let that draft sit.)

The final report format / submission platform — is that settled?

The staged deadlines and the report contents follow the regulation. The ENISA single reporting platform (the intended single point of submission) is still having its registration procedure and templates finalized, so the app is deliberate about not hard-coding a submission form: you export the draft and submit through the current official channel. Templates are built to be updatable as the platform's format is published, and we track those updates.

Plans and pricing

What's free and what's paid?

The Readiness Check — product inventory (including legacy products already on the market), an eligibility check against your Jira/JSM, and a deadline preview — is free. Reporting & Notifications (the five drafts, countdowns, export) and the Vulnerability Register & Drills (standing register, KEV match, tabletop drill mode, report archive) are on the paid plans.

How is it priced, and where do I pay?

Through Atlassian. Billing is handled by the Atlassian Marketplace on your existing Atlassian bill — there is no separate checkout with us. Pricing follows Atlassian's standard per-user tiering across plan levels; see the current figures on the Marketplace listing.

Is there a trial?

Paid plans follow the standard Atlassian Marketplace trial. Start it from the listing or the in-app upgrade screen.

Practical / legal

Is this legal advice?

No. It is a compliance-support tool. It does not provide legal advice and does not guarantee that your obligations are met. Confirm regulatory interpretation with qualified counsel.

Can I practice without filing anything real?

Yes. The tabletop drill mode runs the whole flow — mock incident, draft generation, deadline tracking — without submitting anything. Drafts produced in drill mode carry a visible training watermark, so a practice draft can never be mistaken for a real filing. It is meant for rehearsing your process between real incidents.

Do you support Data Center or Server?

The app targets Atlassian Cloud (Forge). Data Center / Server are not supported.

Contact

Email support@complydraft.com and we will respond within 2 business days.
Please include your site URL and, where relevant, the case ID shown in the app.