Engineering Software Lab (ESL)  |  Case file SRP-DRILL-2026-09-14CoverExhibits24h72hFinal
ESL logo
ESL SBOMator 1.4.7
Software supply-chain evidence for the Cyber Resilience Act

From product scan to ENISA report,
in nine moves

CRA Article 14 reporting obligations apply since 11 September 2026. This file walks through how ESL SBOMator finds the risk, verifies it, and prepares the Early Warning, the 72-hour Notification and the Final Report for the ENISA Single Reporting Platform. Every exhibit is a real 1.4.7 screen; every teleprinter line is real tool output from a labelled drill.

Drill: nothing filed with ENISAReal screenshotsReal tool output
← swipe or use the arrow keys →
Exhibit A  |  Main window, Project Scan, captured 2026-09-13CoverExhibits24h72hFinal
MOVE01

Scan the product once; get SBOM, VEX and HTML report

ESL SBOMator main window, Project Scan tab
A
B
C
Exhibit A. ESL SBOMator 1.4.7, Windows, 1400x900 at 150% DPI.
A
Start a Project ScanOne click runs the parsers, matches CVEs against NVD, OSV, KEV and EPSS, and writes CycloneDX 1.6 SBOM, VEX and an HTML report.
B
ENISA SRPThe CRA reporting workspace is one click from the header, next to FDA 524B evidence.
C
13 workspaces, no clipped titlesProject Scan, Databases, Monitoring, Endpoints, C/C++, AI/ML SBOM, DataBOM, HBOM MPSoC, Devices and more. ENISA SRP opens as a 14th.
Exhibit B  |  Dashboard, ArduPilot scan, 157 componentsCoverExhibits24h72hFinal
MOVE02

Read the whole risk picture on one page

ESL SBOMator dashboard, ArduPilot scan
1
2
3
4
5
Exhibit B. PySide6 dashboard, ArduPilot at commit 37ea692, scan 2026-09-13.
1
157 components, ArduPilotOpen-source flight controller used as the frozen acceptance baseline.
2
32 CVEs, 13 High, 0 CriticalClaimed severity beside computed severity; disagreements are counted, not hidden.
3
100% fix availableEvery finding has a recommended version. Unknowns are excluded from the denominator, never counted as fixed.
4
6 response windows overdueFix published, window passed, still unpatched. The first question a regulator asks.
5
5 dormant findingsFix has existed for over a year. Reachability decides whether they become policy violations.
Exhibit C  |  AI Issues, CI/CD reference verificationCoverExhibits24h72hFinal
MOVE03

Verify the build pipeline itself: 14 CI/CD actions, 14 unpinned

AI Issues tab with CI/CD reference verification table
Exhibit C. GitHub Actions and pre-commit hooks from 32 ArduPilot workflow files.
1
Every uses: line becomes a pkg:github componentThe pipeline is inventoried in the SBOM, not only the application dependencies.
2
Nonexistent owners are flaggedHallucinated or squatted names such as acme-nonexistent-owner/setup-thing are caught before they run in CI.
3
Tag pins get a SHA recommendationactions/checkout@v6 becomes a full 40-character commit pin, ready to paste.
4
The policy gate can fail the buildEnable fail_on_unpinned_actions and the CLI exits 2 with a machine-readable violation list.
Teleprinter T-1  |  tools\srp_drill.py, 2026-09-14 03:42 UTCCoverExhibits24h72hFinal
MOVE04

Awareness at T0: the 24-hour clock starts at once

A labelled drill case: fictitious product, real but long-fixed CVE-2021-44228, nothing sent to ENISA. This is what the tool tells the operator.

ReceivedC:\Sbomator_1.4.x> python tools\srp_drill.py --out C:\tmp\srp-drill == 1. Create AEV case case_id=e28e8ec3-73d3-475b-a6dd-60795a6dc0ea stage=24h status=candidate == 2. Early-warning clock Early warning not yet logged, 24h clock started at 2026-09-14T03:42:11Z; 22h remaining Deadlines: { "early_warning": "2026-09-15 03:42:11+00:00", "notification": "2026-09-17 03:42:11+00:00", "final": "None" # 14 days after the corrective measure is available }
Teleprinter T-2  |  validation against SRP Glossary v1.3CoverExhibits24h72hFinal
MOVE05

Validation refuses an incomplete Early Warning

The seven glossary fields marked X for the 24-hour stage must be present. The tool lists exactly what is missing, then accepts the filled case.

Received== 3. Validation before filling fields missing: Notification type (Vulnerability/Incident) is required for 24h missing: Title is required for 24h missing: Summary is required for 24h missing: Manufacturer name is required for 24h missing: Member States where product available (Concerned CSIRT) is required for 24h missing: Product Name is required for 24h missing: Product Version is required for 24h == 4. Fill early-warning fields Validation errors after filling: none
Teleprinter T-3  |  reportability decisionCoverExhibits24h72hFinal
MOVE06

No package leaves the tool until a human confirms reportability

CRA reporting is a legal decision. SBOMator records who decided, why, and on which evidence, and refuses to export before that decision exists.

Received== 5. Package attempt before reportability decision (expected to be refused) refused as expected: reportability must be confirmed by a user before packaging == 6. Confirm reportability user=drill-operator status=reportable_confirmed rationale="DRILL: simulated reliable evidence of exploitation" evidence=[drill-ticket-001] audit event appended: reportability_decision (sha256 chained to previous event)
Form SRP-24H  |  paste sheet, glossary orderCoverExhibits24h72hFinal
MOVE07

The paste sheet: every portal field, glossary order, copy hint

ENISA offers no API (SRP FAQ 15), so the Assigned Representative transcribes into the web form. SBOMator prepares the exact text in the exact order of the SRP Glossary v1.3.

No.FieldReq.ValueCopy hint
1Notification typeXVulnerabilitySelect the matching portal option
2TitleXTEST EXERCISE - DO NOT SUBMIT - simulated AEV in ESL DrillProductCopy this text into the portal field
3SummaryXTabletop drill. Fictitious product, simulated exploitation of CVE-2021-44228 in bundled log4j-core 2.14.1.Copy this text into the portal field
4Manufacturer nameXEngineering Software Lab (ESL) - DRILLCopy this text into the portal field
5Member States (Concerned CSIRT)XDE, NLSelect or enter all applicable values
6Product NameXESL DrillProduct (fictitious)Copy this text into the portal field
7Product VersionX0.0.0-drillCopy this text into the portal field
19CVE IDOCVE-2021-44228Copy this text into the portal field
Prepared, not submittedPrinted on every generated sheet: "this package is prepared, not submitted, and is not proof of submission."
Teleprinter T-4  |  package manifestCoverExhibits24h72hFinal
MOVE08

The package: four files, one SHA-256 manifest, verifiable years later

Verified== 7. Generate paste sheet and SRP package Package files: ['case.json', 'paste-sheet.html', 'report.html', 'worksheet.csv'] verify_package: True manifest.json { "schema_version": "enisa-srp-glossary-1.3", "regulatory_baseline_date": "2026-09-10", "files": [ { "path": "case.json", "sha256": "08587fcb...8edb8f9e", "size": 10440 }, { "path": "paste-sheet.html", "sha256": "b8030db9...6fcf17cd6", "size": 4884 }, { "path": "report.html", "sha256": "61a70368...e8af8c9", "size": 3050 }, { "path": "worksheet.csv", "sha256": "1717e0cb...ca151ac", "size": 1879 } ] }
1
case.jsonFull case with field provenance, decision history and the hash-chained audit trail.
2
paste-sheet.html and worksheet.csvHuman transcription view and spreadsheet-safe export for the compliance officer.
3
manifest.jsonPinned to glossary v1.3 and regulatory baseline 2026-09-10. verify_package re-hashes every file on demand.
Teleprinter T-5 and Exhibit D  |  submission logCoverExhibits24h72hFinal
MOVE09

Log the portal submission: the clock clears, the case moves to 72h

Logged== 8. Simulate the human portal submission (no real portal contact) Submission log entry: {"stage": "24h", "who": "drill-operator", "submitted_at": "2026-09-14T05:42:28Z", "portal_reference": "DRILL-EW-000001"} Stage after submission: 72h Clock text after submission: '' == 9. Integrity checks audit chain valid: True snapshots valid: True 72h validation errors now: none
ENISA SRP tab, SRP Cases section listing the drill case at stage 72h
D
Exhibit D. ENISA SRP tab, Saved SRP Cases.
D
Saved SRP Cases: aev | 72hThe GUI lists the same case, now at the 72-hour Notification stage. Delete Case removes the drill when the exercise ends.
Schedule Art. 14  |  the three CRA clocksCoverExhibits24h72hFinal

Deadlines are derived from the awareness time, never typed by hand

24 hEarly Warning after awareness of the actively exploited vulnerability or severe incident
72 hNotification with general information and an initial assessment
14 dFinal Report after the corrective or mitigating measure is available (AEV)
1 moFinal Report after the 72h notification (Severe Incident)
Status text shows hours remaining and warns when a deadline is within 6 hours.
A stage cannot be finalized until the previous stage has a recorded submission.
Every edit, decision, export and submission is an event in a SHA-256 hash chain.
Note to file  |  scope of the toolCoverExhibits24h72hFinal
What the tool does not do, on purpose

SBOMator prepares and proves. The Assigned Representative submits.

No automatic upload: ENISA provides no API today (SRP FAQ 15), so submission is a human action in the portal.
No sandbox exists at ENISA. Rehearse with the labelled drill locally; in the real portal only registration, login and a deleted draft are safe.
The package is "prepared, not submitted". Proof of submission is the portal reference you log back into the case.
Reportability is a legal judgement. The tool records it; it never makes it for you.

Portal: portal.cra-srp.enisa.europa.eu  |  FAQ: ENISA SRP FAQ

Case file SRP-DRILL-2026-09-14  |  closedCoverExhibits24h72hFinal
ESL logo
Engineering Software Lab (ESL)

Nine moves. One evidence trail.
Ready for 11 September 2026.

ESL SBOMator 1.4.7: CycloneDX 1.6 and 1.7 SBOM and VEX, readiness counters, CI/CD reference verification, a policy gate for CI, and the ENISA SRP case workflow with paste sheet, package manifest and audit chain.

Windows, Linux, macOSGUI, dashboard, CLIOffline capableCase closed

Related: ESL Solutions for CRA  |  Real-time supply-chain threat detection  |  Hallusquatting protection

1 / 13