Skip to:

Marketplace

CRA Clock for Jira

works with Jira Cloud

OVERALL RATINGS

INSTALLS

1

SUPPORT

  • Partner Supported

TRUST SIGNALS

Showing details for Cloud

Key highlights of the appHold the 24-hour, 72-hour and final report deadlines of Cyber Resilience Act Article 14, on your Jira issues

Qualify before the clock starts

The two conditions of Article 3(42) asked explicitly: reliable evidence of exploitation by a malicious actor, and absence of permission from the system owner. Answers timestamped and attributed.

Three deadlines, computed correctly

24 hours, 72 hours, then the final report. The final report rule changes with the track, and the app applies the right one: 14 days after the fix, or one month after the 72-hour notification.

An evidence file, not scattered notes

Who qualified, when, and what was declared. The record lives in the app storage, never in an editable Jira field, and exports for the market surveillance authority.

Supporting media

More details

CRA Clock for Jira is built and supported from France by Memo Labs. The app interface is in English.

It covers Article 14 of Regulation (EU) 2024/2847 end to end: the two qualification questions of Article 3(42), recorded with their author and timestamp, then the 24 hour early warning, the 72 hour notification and the final report, each with the deadline computed for the right track. A merely exploitable vulnerability under Article 3(41) triggers nothing, and the app says so rather than starting a clock you do not owe.

It is a Forge app eligible for Runs on Atlassian: no outbound calls of any kind, and the evidence record stays in Atlassian hosted storage rather than in an editable Jira field.

Support is by email at contact@memolabs.dev and through our support portal. Response targets and severity levels are written down in the documentation linked from this listing.

Resources

  • App documentation

    Comprehensive set of documentation from the partner on how this app works

Privacy and Security

Privacy policy

Atlassian's privacy policy is not applicable to the use of this app. Please refer to the privacy policy provided by this app's partner.

Partner privacy policy

Security program

This app is not part of the Marketplace Bug Bounty program.

Integration permissions

CRA Clock for Jira integrates with your Atlassian app

Version information

Version 3.5.0•for Jira Cloud

Release date
Sep 9th 2026
Summary
Comment permission is now required to start the clock
Details

Security fix.

The app posts its escalation reminders as Jira comments, so it now checks that you can comment on the issue before it lets you start the clock. Someone with read only access to an issue can no longer cause the app to write on it.

The check uses the Forge Authorize API and runs when you qualify the incident, which is the only moment a user session exists: the reminders themselves are posted later by a scheduled trigger. If the check cannot be completed, the clock does not start.

Payment model
Paid via Atlassian
License type
Commercial

Learn and explore

  • What’s Marketplace
  • App installation
  • About Atlassian
  • Atlassian resources
  • Search and ranking
  • Atlassian events
  • Atlassian foundation

Follow