4 In Case of Incident: Vulnerability Handling and Reporting
Phase I of the CRA comes into full effect on September 11, 2026. Phase one requires manufacturers to comply with the full reporting requirements prescribed by the CRA. This section describes what the requirements are and what to do next.
What are the Requirements for Handling and Disclosing Vulnerabilities to End-users?
Vulnerability Documentation
Manufacturers must identify and document vulnerabilities for at least the top-level dependencies of their product. This document must be in a common and machine-readable format. The SBOM is just part of this documentation. It can be maintained internally or shared with customers if required or appropriate, but the CRA specifically requires it to be available to market surveillance authorities when needed for compliance checks.
Regular Tests and Reviews
Effective and regular security tests and reviews of the product must be conducted and documented properly.
Public Disclosure of Vulnerabilities
Information about potential and fixed vulnerabilities in the products and the third-party components within the product must be disclosed and shared with the public once a security update is available, in addition to notifying the European Union Agency for Cybersecurity (ENISA). This information must allow users to identify the affected product, the impact and severity of the vulnerability, and how to fix or address it. Additionally, information about where to find a list of vulnerabilities and where to report them must also be disseminated clearly and widely.
Coordinated Vulnerability Disclosure Policy
The CRA requires manufacturers to establish and enforce a policy on disclosing incidents and vulnerabilities.
Timely Security Patches Free of Charge
As part of vulnerability handling obligations, manufacturers are responsible for distributing security patches or updates to address identified security issues without delay and free of charge. These updates must be accompanied by advisory messages providing users with relevant information, including the potential action to be taken.
What Incidents Must be Reported?
Manufacturers must notify relevant authorities, such as the ENISA, through the CRA's Single Reporting Platform (SRP) if they become aware of the following:
- Any actively exploited vulnerability contained in its product
- Any severe incident having an impact on the security of the product
Once the manufacturer becomes aware of the event, the clock starts. “Becoming aware” is defined as having a reasonable degree of certainty that a vulnerability is actively exploited or a severe security incident exists. For example, when unusual network activity is detected, it is not necessarily “becoming aware.” Once an assessment has confirmed that malicious activity has indeed occurred, the company is now “aware,” and the clock officially starts. Manufacturers must have an effective vulnerability-handling and incident-reporting capability. In practice, many organizations implement this through a Product Security Incident Response Team, or PSIRT, but the CRA does not require that every manufacturer use that exact term.
How Much Time Can Pass Between Reporting an Incident and Filing a Report?
Manufacturers are required to submit early warning notifications containing limited information without undue delay and, in any event, within 24 hours of becoming aware.
Additional information is required as part of the notification to be submitted without undue delay and, in any event, within 72 hours of becoming aware (’72-hour notification’). The complete report needs to be submitted within 14 days after a corrective or mitigating measure is available for actively exploited vulnerabilities, or within one month after the 72-hour notification for severe incidents.
| Time | Action |
|---|---|
| 24 hours after being aware | Submit an early warning notification containing limited information |
| 72 hours after being aware | Complete all information required as part of the notification |
| 14 days after corrective action or mitigating measure | Submit a complete report for actively exploited vulnerability |
| 1 month after the 72-hour notification | Submit a complete report for severe security incident |
Users may also need to be informed without undue delay where the vulnerability or incident could adversely affect the security of the product or users’ systems.
For additional information on reporting incidents and filing reports, refer to ENISA's SRP FAQ page.
Action Checklist
- Review security testing procedures in place for development processes.
- Check if a defined and documented internal workflow and policy exists for emergency security reporting and disclosures.
- Establish a public vulnerability disclosure pathway to communicate incidents and issues outside the company.
- Ensure that there are resources for a dedicated PSIRT.
- Determine if vendors have a PSIRT process in place.
