OVERALL RATINGS
INSTALLS
2
SUPPORT
- Partner Supported
TRUST SIGNALS
Key highlights of the appDraft CRA Article 14 incident reports and vulnerability reporting in Jira & JSM — deadlines tracked, data never leaves your tenant
Article 14 draft set, from your tickets
Generate drafts for each Article 14 stage — early warning, notification, final report, user notice and upstream notice — straight from a Jira or JSM issue, ready for your team to review
Staged deadlines from the correct start point
Vulnerability final report 14 days after a fix is available; severe-incident final report one month after the 72-hour notification is submitted. The distinction is built in and each stage counts down separately
Runs on Atlassian — zero data egress
Only Atlassian-hosted compute and storage, so incident data never leaves your tenant. The KEV match uses a bundled snapshot with a visible as-of date, not a live feed, and every action is written to an append-only log
Supporting media
More details
CRA Reporting Copilot is for manufacturers placing products with digital elements on the EU market who already run incident response in Jira or Jira Service Management. The EU Cyber Resilience Act applies its Article 14 reporting duty from 11 September 2026, on a staged timeline where each stage starts from a different point.
The app tracks each staged deadline from its correct start point, generates draft reports and notifications for your team to review, and writes every action to an append-only audit log. Boundary cases are flagged for human confirmation, and nothing is submitted on your behalf.
It runs entirely on Atlassian infrastructure with no external egress and no LLM. Data stays inside your own tenant. English-language interface. This is a compliance-support tool, not legal advice.
Resources
App documentation
Comprehensive set of documentation from the partner on how this app works
Privacy and Security
Privacy policy
Atlassian's privacy policy is not applicable to the use of this app. Please refer to the privacy policy provided by this app's partner.
Partner privacy policySecurity program
This app is not part of the Marketplace Bug Bounty program.
Integration permissions
CRA Reporting Copilot - Compliance & Incident Reporting integrates with your Atlassian app
Version information
Version 4.1.0•for Jira Cloud
- Release date
- Jul 29th 2026
- Summary
- Permission model hardened: product reads now run as the invoking user
- Details
Security: Jira and JSM reads now use asUser(), so per-user permissions are enforced natively by the product. A regression test covers the case of a user without browse permission. Dependencies: @forge/api upgraded to 8.x and @forge/react to 12.x. No functional or scope changes.
- Payment model
- Paid via Atlassian
- License type
- Commercial