Memo Labs

Documentation, CRA Clock for Jira

For app version 3.2.0. Last updated 9 September 2026.

CRA Clock holds the three notification deadlines of Article 14 of Regulation (EU) 2024/2847, the Cyber Resilience Act, on the Jira issue your team already works on. It does not submit anything on your behalf and it is not legal advice.

1. Install and find the app

Install from the Atlassian Marketplace. A Jira administrator has to approve the app's permissions once. After that, open any issue: the panel is called CRA article 14 and sits in the right hand column, under Automation. Expand it to start.

The app asks for three permissions and nothing else: read the issue it is displayed on, post its escalation comments there, and use its own app storage. It makes no outbound calls of any kind, which is what qualifies it for the Runs on Atlassian programme.

2. Qualify the incident before anything starts

The clock does not start on just any vulnerability. Article 3(42) defines an actively exploited vulnerability by two conditions, and the app asks both:

Pick the track, Actively exploited vulnerability or Severe incident, answer both questions, then give the date you became aware, in ISO format. That date is what starts the deadlines, so take a moment over it.

If only one condition is met, Start the clock refuses and explains why: under Article 3(41) this is an exploitable vulnerability, which triggers no notification obligation. Nothing is saved. This refusal is deliberate. An alarm you did not owe is as expensive as a deadline you missed.

The answers are recorded with the account that gave them and the exact time.

3. Read the three deadlines

Once the clock runs, the panel shows three reports, each with its due date and the time left:

The final report is where the regulation is easy to get wrong, so the app applies the rule of the track you chose. On a vulnerability, it falls 14 days after the fix becomes available: until you fill in that date, there is no final deadline, and the app says so instead of inventing one. On a severe incident, it falls one month after the 72 hour notification.

Each report carries a status: on track, due soon, overdue, or sent.

4. File each report

Every report has the fields Article 14 expects for that stage. Fill them in and use Save draft as often as you like.

When you have actually sent the report to your coordinating CSIRT and to ENISA, click Mark as sent. The app records who marked it and when, and freezes the content. A record that can be rewritten afterwards proves nothing, which is why freezing is not optional.

The app never submits anything for you. The single reporting platform is not something we call, and the app makes no outbound requests at all.

5. Escalations on the issue

Before each deadline the app posts a comment on the issue naming the report, its due date, the time left, and the recipients. It runs on a schedule, weekends and evenings included, which is the point: Article 14 does not pause on a Friday night.

An escalation is claimed before it is posted, so a deadline is announced once and not twice.

6. Export the record

Export the record opens the full file: the qualification with its author and timestamp, the computed deadlines, every report with what was declared and when it was marked sent, and the whole event history. Select the text to copy it.

This is the file to hand to a market surveillance authority, which under Article 52 is the body that can ask.

7. Where the data lives

Everything is stored in the app's own Forge storage on Atlassian infrastructure, never in an editable Jira custom field, so the trail cannot be quietly rewritten from the Jira interface. Data residency, where your Atlassian subscription includes it, applies to the app's storage as part of your instance. The detail is in the privacy policy.

8. Licensing

The app is paid via Atlassian, with the 30 day free trial that every Marketplace app carries. Without an active subscription, reading and exporting keep working: no new clock can be started and no report can be filed, but the records you already have stay readable and exportable. We do not hold a customer's compliance evidence hostage.

9. Limits worth knowing

10. Support

Write to contact@memolabs.dev. Monday to Friday, critical issues answered within 24 hours, other requests within 5 business days. Include the issue key and, if you can, the exported record.