Article 14 reporting applies from 11 September 2026
Menu
Article 14 reporting applies from 11 September 2026

About

Makers who sell software or connected hardware in the EU must now report exploited security flaws within 24 hours. PartsProof builds the documents you need from one order form.

PartsProof builds documents from your answers. The Cyber Resilience Act's reporting duties started on 11 September 2026 and assume three things already exist: a published disclosure policy, an SBOM, and a runbook that can produce a notification inside twenty-four hours. Most small makers have none of the three. You fill in one order form. PartsProof generates the documents from it, and you publish and sign them.

The SBOM generator on the front page walks a public GitHub repository and builds a real bill of materials from what is actually in it. It is free, needs no account, and works whether or not you ever buy anything.

The record

  • Builds the security documents the EU now requires from small makers who sell software or connected hardware there
  • Published by Compound Labs
  • Live at partsproof.thecompound.tech
  • 38 registered claims, 38 of them carrying the primary source they came from
  • Every one of them re-verified against that source on or after 10 September 2026
  • Whether it is up right now: the status page, measured from outside this site

The figures in that record are counted from this product's own claim register rather than written beside it, and the date is the OLDEST verification in the set rather than the newest — a register is only as fresh as its stalest entry, and the newest date is the flattering answer. Nothing here is a round number somebody remembered.