When something you ship is being exploited, the clock starts.

Meldklok watches your SBOMs against the EU and CISA exploitation feeds, starts the Cyber Resilience Act deadlines the moment you confirm awareness, and hands you a prefilled dossier for each one.

Ready to submit the early warning within 24 hours, with the evidence of who knew what and when.

  • 24h Early warning, from the moment you become aware
  • 72h Full notification, from that same moment
  • 14d Final report, after a corrective measure is available

How it works

1. Upload an SBOM

One CycloneDX or SPDX file per product release, through the app or with a curl call from your build. Meldklok parses the components and tells you which ones carry a package URL and which ones will match weakly.

2. We watch the exploitation feeds

Every day the EUVD known exploited dump, every four hours the exploited vulnerabilities endpoint, and the CISA catalogue next to them. A match on an active component alerts your notifier and the backup.

3. Confirm awareness and the clocks run

One click records the awareness moment in an append only trail. The three deadlines start, the dossier for each phase is prefilled with what we already know, and reminders follow the window, not your calendar.

The first 24 hours

The walkthrough below is the scenario Meldklok is built around. The times are the ones the tool aims for, not a promise about your incident.

  • T+0:00 System: The feed job ingests the EUVD dump and matches a component in the SBOM of one of your products.
  • T+0:05 System: A finding and a draft incident are created. The notifier and the backup get the alert with product, component, vulnerability id and source.
  • T+0:20 Notifier: The notifier confirms awareness. The timestamp is recorded and cannot be moved afterwards. Three countdowns start.
  • T+0:30 Notifier: The triage checklist is answered: is the component reachable, is the version really shipped, is exploitation relevant. Every answer is logged.
  • T+1:00 Notifier: The 24 hour dossier is open. Everything the system holds is already filled in; the free text fields carry templates.
  • T+1:30 Backup: The backup reviews and approves inside the tool. The approval is logged, and the deadline still wins over the review.
  • T+2:15 Notifier: The reporter submits in the Single Reporting Platform, marks the phase submitted and pastes the reference. About 21 hours of margin left.

What you get

Monitor what you actually ship

Matching runs against the SBOM you marked active, so an alert is about the release in the field.

  • EUVD known exploited dump and exploited vulnerabilities endpoint
  • The CISA known exploited catalogue as a second source
  • OSV advisories as an informational list that never starts a clock
  • Every match carries a confidence: exact, probable or weak, and you choose what alerts

A clock you can defend

The awareness moment is a decision by a person, recorded once and never changed.

  • 24 hours, 72 hours and the final report as live countdowns
  • Reminders at half and at four fifths of each window, and at breach
  • An append only audit trail with a hash chain per incident
  • Export the trail as PDF or JSON, with a manifest you can verify offline

A dossier ready to paste

The Single Reporting Platform has no API, so the work is to make the copying trivial.

  • Fields in the order of the form, each with a copy button
  • Prefilled with product, manufacturer, component, vulnerability and the coordinating CSIRT
  • Editable templates for the free text answers
  • Four eyes review when you want it, lifted automatically when the deadline gets close

Evidence in one place

The vault holds the documents that the December 2027 requirements ask for, versioned.

  • CVD policy, risk assessment, support period statement, technical documentation
  • A readiness bar per product, so a gap is visible before someone asks
  • One evidence package as a ZIP, with hashes in the manifest
  • Old versions stay readable and read only

European by default

The application, the database and the backups run on EU infrastructure.

  • Hosted in Germany or Finland
  • Fonts and assets ship with the application, so no request leaves for a CDN
  • Every subprocessor is named in the data processing agreement
  • Two factor authentication is required for admins and notifiers

Not sure the CRA applies to you?

Answer eight questions and get an indicative answer with the reasoning behind it, without an account. The result is indicative and not legal advice.

Run the free scope check

Pricing

You pay for the products you monitor. Register one product and try everything for 14 days; after that a subscription is needed to add products, upload SBOMs and switch monitoring on.

  • Annual: €99 per product per month. Billed once a year, €1188 per product. 60% below the monthly plan.
  • Monthly: €249 per product per month. Billed monthly. Cancel at any time; the subscription runs to the end of the period.

Questions

Who is Meldklok for?

Manufacturers of products with digital elements that sell in the EU, typically with five to fifty engineers and no security team of their own. If you ship software or a connected device and you would have to report an actively exploited vulnerability, this is built for you.

When does the reporting duty start?

Article 14 of the Cyber Resilience Act, Regulation (EU) 2024/2847, applies from 11 September 2026. The duty also covers products that were placed on the EU market before the CRA.

Which deadlines does the clock track?

An early warning within 24 hours, a full notification within 72 hours, and a final report no later than 14 days after a corrective measure is available. For severe incidents the final report is due within one month after the initial notification.

Does Meldklok submit the report for me?

No. The Single Reporting Platform of ENISA has no API, so submission is a manual action in a web form after registration with EU Login. Meldklok prepares the dossier in the order of that form and records the moment you mark it submitted. A human submits.

Which sources do you monitor?

The EUVD known exploited dump, the EUVD exploited vulnerabilities endpoint and the CISA known exploited catalogue. Their union is the match set, and the source of every record is stored. OSV is queried as an informational advisory list: it never alerts and never starts a clock.

Which SBOM formats can I upload?

CycloneDX JSON and SPDX JSON, up to 20 MB per file. Upload in the app or from your build with a token authenticated call. Components with a package URL match precisely; components without one match weakly, and Meldklok tells you how many of those you have.

How do I know whether the CRA applies to my product?

Run the free scope check. Eight questions give an indicative answer, an indicative class and the reasoning trail behind it. The question set follows the Commission guidance and is marked to verify, because that guidance is still settling. The result is indicative and never legal advice.

Where does my data live?

On EU infrastructure: the application, the database and the backups run in Germany or Finland. Every subprocessor is named in the data processing agreement. Stripe processes billing data outside the EU, which is why it is named there explicitly.

Is this legal advice?

No. Meldklok is a software tool. It does not decide whether an event is reportable and it makes no claim that you are compliant. The scope check, every finding and every dossier carry that line as well.

What does it cost, and what if a payment fails?

Two plans, €99 per product per month billed annually or €249 per product per month billed monthly, both excluding VAT. A failed payment never blocks an open incident: you keep viewing, working the dossier and exporting the trail. It gates adding products, uploading SBOMs and switching monitoring on, after a grace period.

Be ready before 11 September 2026

Create an account, register one product and upload an SBOM. Onboarding takes under an hour. The first 14 days are free and no card is needed to start.

Create an account