CyresoraSelf-Hosted NIS2 & CRA Register: Reporting Clocks, Vulnerabilities, Rota
Self-hosted NIS2 and CRA readiness register: every reporting deadline counted in hours from the moment you found out, with what you sent and to whom. Bought once.
No sign-up, no password — the demo opens already signed in, on sample data.
- Full PHP source included
- Instant download + licence key
- It never phones home
- Compare vs SaaS pricing →
The problem it solves
A self-hosted NIS2 reporting register matters the day you fall in scope, because the reporting clocks run in hours from the moment you found out — and an enterprise GRC platform is a lot of machinery for keeping that record straight. Cyresora is $79 once: deadlines counted in hours, what you sent and to whom, vulnerabilities and the rota, in plain PHP on your own server.
From 11 September 2026, Article 14 of the Cyber Resilience Act makes a manufacturer file an early warning about an actively exploited vulnerability or a severe incident without undue delay — within 24 hours at the outside. NIS2 has required the same 24 hours of essential and important entities since transposition.
There is no version of that timetable in which you work out the process while the clock is running. And a single event routinely triggers both regimes at once, each with its own ladder off the same moment of awareness.
- Deadlines tracked in someone's head during the one week nobody has spare attention
- Enterprise GRC or an incident-response retainer, neither of which a 30-person manufacturer buys
- No record of what was actually sent, to whom, and when — which is the only thing that stops a clock
What you get
Every running deadline, worst first, in hours remaining. During an incident this is the only screen anyone opens, which is why it is the home screen.
A single event routinely triggers the CRA and NIS2 at once. Each regime gets its own ladder off the same moment of awareness, with its own anchors — rather than one merged timeline that is wrong for both.
To whom, when, through what channel, with their reference and the text kept. That record is what stops a clock, so it is its own permission: a member can work an incident, but declaring that a report went out needs notify.submit. Filing the same stage twice is refused by a unique index, because a duplicate is not a second duty discharged.
Actively exploited, and the date a corrective measure became available — the event the CRA final-report clock waits for. Not a CVE feed and not a scanner: the handful you are actually handling.
Whether a product has digital elements, or whether you are an essential or important entity, is a decision with legal consequences. You mark it, with your reasoning recorded beside it. The register does not decide it and does not guess.
Who notifies, who decides, their deputies, out-of-hours numbers, and the national authority each one deals with — the list nobody can find at 2am.
A per-incident report PDF with every ladder and everything sent, plus CSVs of the reporting register one row per stage, the vulnerabilities, and an evidence manifest.
The 3.1 wave gave the catalogue a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Every outbound path ships switched off, runs on your own credentials, and can never break the thing that triggered it. This app gained no new outbound path in 3.1 — its pass rewrote the honest-limitations list against the shipped code instead, which is the more useful change when the product was already complete.
See it running — right now, on sample data
No sign-up, no password — it opens already signed in, and resets itself. Click around freely.
Open the live demoIs Cyresora right for you?
Before the price, not after it: what Cyresora deliberately does not do. We publish this on every product because the wrong purchase costs you more than the price.
- Not legal advice, and not a scope determination — it records your determination and your reasoning, it does not make it
- NIS2 is a Directive — it models the Directive's own stages, not 27 national transpositions
- It does not file anything. No integration with the CRA single reporting platform or any national portal
- Not a vulnerability scanner and not a CVE feed — a register of what you are handling, not a discovery tool
- No SOC, no SIEM, no detection — the clock starts when you record that you became aware
- Single-tenant: one organisation per installation
Still the right fit? See the price → · Not sure — see who should stay with the SaaS →
Pricing — one-time, yours forever
- ✔ Full source included — PHP you can read and change
- ✔ No subscription. One payment, yours forever
- ✔ It never phones home
- ✔ Your data stays on your server
- ✔ 14-day refunds — we’d rather refund than argue
- ✔ Offline test suite in the box — run it before you rely on it
- ✔ If we ever stop: after 1 year the domain limit lifts, after 3 years your copy relicenses to MIT — it’s in the licence
Not ready to own it? Ownware Cloud runs selected apps from $12/month — and after 12 paid months the perpetual self-host licence is yours.
Read before you buy — what the zip looks like inside
cyresora/
README.md · QUICKSTART.txt · LICENSE.txt
app/
index.php · router.php · config.sample.php · Dockerfile
src/ the classes — plain PHP 8, no framework, no Composer
controllers/ every route handler
views/ every screen
tests/ the offline test suite — run it yourself: php tests/run.php
bin/ packaging · seeding · maintenance scripts
API.md the REST + webhook + MCP reference
Nothing is obfuscated or encoded. What you read is what runs.
Which licence do I need?
It comes down to how many installations you need. Running your own business on one site is the Single licence. Building or running sites for other people — a second domain of your own, or an installation a client keeps — is the Extended licence.
Single licence
One (1) domain or subdomain
One business, running it on one site.
- Install it on one domain or subdomain you own or operate
- Change the source however you like for that installation
- Run your own business on it commercially, client work included
- Re-download the current build any time from your buyer portal
- A second site, or an installation you hand to a client as theirs, needs the Extended licence
- No reselling, redistributing or sublicensing the source
- Not for offering it to other people as a hosted service
Extended licence
Unlimited sites you own or operate
Agencies, and anyone running it on more than one site.
- Everything the Single licence grants
- Install it on as many domains as you own or operate — no cap on the number
- Build and hand over one installation per client project
- Still no reselling or redistributing the source itself
- Running it as a multi-tenant service others sign up for needs a SaaS agreement
Every download carries the full terms as LICENSE.txt, and the licence you bought is
named on your order and in your buyer portal. The complete wording lives on the
terms page, and the live demo is free for as long
as it takes to decide.
No reviews yet — so here is what we offer instead. Every competitor price on our comparison pages is source-linked and dated, and when a vendor’s price won’t load we say so rather than guess. See the sources for yourself →
After you buy
The four things people ask right before they decide.
Your download link always serves the current build at the time you fetch it — re-download any time from your order page or the buyer portal. No renewal fee to keep what you bought.
Email support for installation and for defects in the code as delivered — a person answers, usually within a day or two. It does not cover custom development or server administration. What support covers →
Refunds are handled by Lemon Squeezy as Merchant of Record, case by case — if something is broken and we can’t fix it, we’d rather refund than argue. EU consumers additionally hold the statutory 14-day right until delivery starts. Refund terms →
Nothing stops. You hold the full PHP source, it runs on your own server, and the software does not phone home — there is no licence check that can fail and no cloud that can be switched off. LICENSE.txt ships inside the zip, so your right to keep running it never depended on this site existing.
Covered in these guides
Article 14 gives a manufacturer 24 hours at the outside — the duty itself starts the moment you become aware. The part that catches people is not the 24 — it is that the final-report clocks do not run from when you found out, and that none of these deadlines pause at the weekend.
Questions about Cyresora
Does it file the report for me?
No. There is no integration with the CRA single reporting platform or any national portal, and no API for one this product could use. You file; you record what you filed. The register job is that you file in time and can prove it.
NIS2 is a Directive — whose version does this model?
It models the Directive own stages and records your national authority and any variation you have been told about. It does not model 27 national transpositions and does not pretend to. What binds you is your Member State law.
Does it decide whether I am in scope?
No, and that is deliberate. Whether a product falls under the CRA, or whether you are an essential or important entity, is a legal question. The register records your determination and your reasoning.
Is this a vulnerability scanner or a CVE feed?
Neither. It is a register of the vulnerabilities you are actually handling, with the two dates the regulations turn on: actively exploited, and corrective measure available.
Where does the data live?
On your server. Plain PHP 8 with MySQL or MariaDB — SQLite for a trial — no Composer and no build step. Your incident file does not sit in someone else cloud.
