Vulnerability Management Under the CRA
The Cyber Resilience Act places significant emphasis on vulnerability management—how manufacturers identify, handle, and remediate security vulnerabilities in their products. This isn't just about fixing bugs; it's about having systematic processes in place.
Why Vulnerability Management Matters
Vulnerabilities are inevitable in software. What matters is how quickly and effectively you respond. The CRA ensures that manufacturers take responsibility for security throughout the product lifecycle, not just at launch.
Key CRA Vulnerability Requirements
The CRA's Annex I, Part II outlines 8 requirements specifically focused on vulnerability handling:
- Identify and document vulnerabilities (including in dependencies)
- Address vulnerabilities without delay
- Apply regular effective security testing
- Disclose information about fixed vulnerabilities
- Implement a coordinated vulnerability disclosure policy
- Share vulnerability information
- Distribute security updates securely and for free
- Maintain a Software Bill of Materials (SBOM)
Coordinated Vulnerability Disclosure (CVD)
One of the most significant CRA requirements is establishing a Coordinated Vulnerability Disclosure (CVD) policy. This is how external security researchers can safely report vulnerabilities to you.
What Your VDP Must Include
Contact Information
A clear way to report vulnerabilities—typically a security@yourcompany.com email or a web form.
Response Timeline
Commitment to acknowledge reports within a reasonable timeframe (e.g., 5 business days).
Safe Harbor Statement
Assurance that good-faith security researchers won't face legal action.
Disclosure Timeline
When and how you'll publicly disclose fixed vulnerabilities.
Need help creating your Vulnerability Disclosure Policy?
VDP Builder Tool →Reporting Vulnerabilities to Authorities
The CRA introduces mandatory reporting obligations to EU authorities. Starting September 2026, manufacturers must report certain vulnerabilities and incidents.
What Must Be Reported
Actively Exploited Vulnerabilities
Within 24 hours of becoming aware
- Report to ENISA and national CSIRT
- Include affected products and severity
- Preliminary mitigation if available
Full Vulnerability Notification
Within 72 hours of awareness
- Applies only to actively exploited vulnerabilities (not merely high/critical-severity, unexploited ones — those are not a CRA reporting trigger)
- Full details replacing the 24-hour early warning
- Update when more info available
Reporting Timeline
Early Warning
Initial notification for actively exploited vulnerabilities
Vulnerability Notification
Detailed report with technical information
Vulnerability Final Report
Description of the vulnerability, malicious-actor info, and security update/corrective measure details — clock starts when a fix or mitigation becomes available, not from discovery. (Separately, a severe-incident final report with root cause is due one month after the 72-hour incident notification — a distinct track.)
Reporting Obligations Start September 2026
While other CRA requirements apply from December 2027, vulnerability and incident reporting obligations to ENISA become mandatory 21 months after entry into force—around September 2026. Start preparing your incident response processes now.
Security Update Requirements
The CRA mandates that manufacturers provide security updates throughout the product's support period:
Free of Charge
Security updates must be provided free of charge to users. You cannot charge for security patches.
Timely Distribution
Updates must be made available without undue delay after vulnerabilities are identified.
Secure Delivery
Updates must be distributed securely (e.g., signed updates) to prevent tampering.
User Notification
Users must be notified about available security updates and the vulnerabilities they address.
Support Period
Updates must be provided for at least 5 years from placing the product on market, or the product lifetime if less than 5 years.
Vulnerability Management Implementation Checklist
Use this checklist to assess your readiness for CRA vulnerability management requirements:
Establish a Security Contact
Create security@yourcompany.com and/or a security.txt file pointing to your VDP.
Create security.txt →Publish Vulnerability Disclosure Policy
Create and publish a VDP on your website explaining how to report vulnerabilities.
VDP Builder →Set Up Vulnerability Tracking
Implement a system to track reported vulnerabilities from intake to resolution.
Create Incident Response Procedures
Document how your team will respond to security incidents, including escalation paths.
Prepare Reporting Templates
Create templates for ENISA/CSIRT reporting to meet 24/72-hour deadlines.
Implement Secure Update Infrastructure
Ensure you can distribute signed updates to all deployed products.
Generate and Maintain SBOM
Create an SBOM to quickly identify affected products when vulnerabilities are discovered.
SBOM Requirements →Vulnerability Management FAQ
How quickly must I patch a vulnerability?
The CRA requires vulnerabilities to be addressed "without undue delay." For actively exploited vulnerabilities, this effectively means as fast as possible. The specific timeline may depend on severity and complexity, but the expectation is rapid response—typically days, not weeks.
What if a third-party component has a vulnerability?
As the manufacturer, you're responsible for your entire product—including third-party components. You must monitor dependencies (using SBOM) and distribute updated versions of your product with patched components. Work with your suppliers or update to patched versions.
Do I need a bug bounty program?
The CRA does not require a paid bug bounty program. However, you must have a way for researchers to report vulnerabilities (coordinated vulnerability disclosure). Whether you offer bounties is a business decision, but having a clear VDP is mandatory.
What testing is required?
The CRA requires "regular and effective" security testing. This includes vulnerability scanning, penetration testing, and code review as appropriate. The specific testing approach should be risk-based and documented as part of your security process.
Build Your Vulnerability Management Program
Start with our free VDP builder tool and SBOM generator guide.