Your Cart
Loading

Context Zero — 24-Hour Decision Playbook

On Sale
€97.00
€97.00
Added to cart

For manufacturers of products with digital elements placed on the EU market. Not for companies that only use those products.


From 11 September 2026, Article 14 of the Cyber Resilience Act is in force.


If you manufacture a product with digital elements and place it on the EU market, and that product is already being exploited — or a severe incident hits its security — the first notice is due within 24 hours of the manufacturer becoming aware. A fuller notice follows within 72 hours. You file once, through ENISA’s Single Reporting Platform.


Detection is usually not the problem.

The problem is the room.


Who is allowed to say the company is aware.

Who owns the filing.

What happens when Security and Legal disagree.

What happens when the person with authority is on a plane.


The Act does not give you 24 hours to build consensus.

It gives you 24 hours for the first report.


This is a short publication from Context Zero: a quiet-day card, the order of the first day, a working sheet for the early warning, and a drill. It is preparation. It is not an audit, not a filing, and not legal advice.


The official text of Regulation (EU) 2024/2847 prevails.


You do not have a reporting problem if the 24 hours are spent finding who can decide.


You have a decision-architecture problem.


CRA gives you 24 hours to report.

Context Zero makes sure you don’t spend those 24 hours figuring out who can decide.


WHAT YOU GET

– 7-page PDF

– Quiet-day card (names, CSIRT path, SRP account)

– Order of the first 24 hours

– Early-warning working sheet

– Disagreement table

– Timed drill (Context Zero method, not an ENISA case)


WHAT YOU DO NOT GET

– Legal advice

– A completed ENISA filing

– A conformity assessment

– A guarantee of compliance



Issued by Renata Amare and Vitali Amare. Working edition, 11 September 2026.

You will get a PDF (57KB) file