🔒All inputs are processed locally in your browser. Nothing is transmitted, stored, or logged. Inputs disappear when you close the tab.

OCG-Industries Showcase · Cluster ⑩ Software and Cybersecurity Supply Chain

VEX Vulnerability
Disclosure Timeline

Enter a discovery hour and the hour index at which you filed each disclosure step, and this tool checks each step against the CRA cascade of 24 hours, 72 hours, and 14 days. The windows are frozen values built into the page, not read from a clock, so a step is stamped on time or late purely from the hours you type in. Re-run the same hours and the same result comes back, which is what makes a lateness finding a derived fact rather than a claim in a spreadsheet.

Data: Regulation (EU) 2024/2847 (Cyber Resilience Act) Art.14 · OpenVEX specification

Timeline STEP 1
Hour index zero, your own reference point for the clock
Use -1 if not yet filed. Due within 24 hours of discovery
Use -1 if not yet filed. Due within 72 hours of discovery
Use -1 if not yet filed. Due within 336 hours (14 days) of discovery
Cascade Status
Compliant, incomplete, or late
Late Steps
Steps filed after their due hour
Final Report
Status of the 14 day step
Detail
Discovery hour
Early warning due hour
Early warning status
Early warning slack (hours)
Notification due hour
Notification status
Notification slack (hours)
Final report due hour
Final report status
Final report slack (hours)
Late step count
Status
Policy Mandate v2.0 · what is this?