← Back to CRA Guide

CRA Vulnerability Management Requirements

The Cyber Resilience Act requires robust vulnerability handling throughout your product's lifecycle. Learn about disclosure, patching, reporting, and coordinated response.

Last updated: September 5, 2026

Vulnerability Management Under the CRA

The Cyber Resilience Act places significant emphasis on vulnerability management—how manufacturers identify, handle, and remediate security vulnerabilities in their products. This isn't just about fixing bugs; it's about having systematic processes in place.

Why Vulnerability Management Matters

Vulnerabilities are inevitable in software. What matters is how quickly and effectively you respond. The CRA ensures that manufacturers take responsibility for security throughout the product lifecycle, not just at launch.

Key CRA Vulnerability Requirements

The CRA's Annex I, Part II outlines 8 requirements specifically focused on vulnerability handling:

  • Identify and document vulnerabilities (including in dependencies)
  • Address vulnerabilities without delay
  • Apply regular effective security testing
  • Disclose information about fixed vulnerabilities
  • Implement a coordinated vulnerability disclosure policy
  • Share vulnerability information
  • Distribute security updates securely and for free
  • Maintain a Software Bill of Materials (SBOM)

Coordinated Vulnerability Disclosure (CVD)

One of the most significant CRA requirements is establishing a Coordinated Vulnerability Disclosure (CVD) policy. This is how external security researchers can safely report vulnerabilities to you.

What Your VDP Must Include

1

Contact Information

A clear way to report vulnerabilities—typically a security@yourcompany.com email or a web form.

2

Response Timeline

Commitment to acknowledge reports within a reasonable timeframe (e.g., 5 business days).

3

Safe Harbor Statement

Assurance that good-faith security researchers won't face legal action.

4

Disclosure Timeline

When and how you'll publicly disclose fixed vulnerabilities.

Need help creating your Vulnerability Disclosure Policy?

VDP Builder Tool →

Reporting Vulnerabilities to Authorities

The CRA introduces mandatory reporting obligations to EU authorities. Starting September 2026, manufacturers must report certain vulnerabilities and incidents.

What Must Be Reported

Actively Exploited Vulnerabilities

Within 24 hours of becoming aware

  • Report to ENISA and national CSIRT
  • Include affected products and severity
  • Preliminary mitigation if available

Full Vulnerability Notification

Within 72 hours of awareness

  • Applies only to actively exploited vulnerabilities (not merely high/critical-severity, unexploited ones — those are not a CRA reporting trigger)
  • Full details replacing the 24-hour early warning
  • Update when more info available

Reporting Timeline

24 hours

Early Warning

Initial notification for actively exploited vulnerabilities

72 hours

Vulnerability Notification

Detailed report with technical information

14 days after fix available

Vulnerability Final Report

Description of the vulnerability, malicious-actor info, and security update/corrective measure details — clock starts when a fix or mitigation becomes available, not from discovery. (Separately, a severe-incident final report with root cause is due one month after the 72-hour incident notification — a distinct track.)

Reporting Obligations Start September 2026

While other CRA requirements apply from December 2027, vulnerability and incident reporting obligations to ENISA become mandatory 21 months after entry into force—around September 2026. Start preparing your incident response processes now.

Security Update Requirements

The CRA mandates that manufacturers provide security updates throughout the product's support period:

Free of Charge

Security updates must be provided free of charge to users. You cannot charge for security patches.

Timely Distribution

Updates must be made available without undue delay after vulnerabilities are identified.

Secure Delivery

Updates must be distributed securely (e.g., signed updates) to prevent tampering.

User Notification

Users must be notified about available security updates and the vulnerabilities they address.

Support Period

Updates must be provided for at least 5 years from placing the product on market, or the product lifetime if less than 5 years.

Vulnerability Management Implementation Checklist

Use this checklist to assess your readiness for CRA vulnerability management requirements:

1

Establish a Security Contact

Create security@yourcompany.com and/or a security.txt file pointing to your VDP.

Create security.txt →
2

Publish Vulnerability Disclosure Policy

Create and publish a VDP on your website explaining how to report vulnerabilities.

VDP Builder →
3

Set Up Vulnerability Tracking

Implement a system to track reported vulnerabilities from intake to resolution.

4

Create Incident Response Procedures

Document how your team will respond to security incidents, including escalation paths.

5

Prepare Reporting Templates

Create templates for ENISA/CSIRT reporting to meet 24/72-hour deadlines.

6

Implement Secure Update Infrastructure

Ensure you can distribute signed updates to all deployed products.

7

Generate and Maintain SBOM

Create an SBOM to quickly identify affected products when vulnerabilities are discovered.

SBOM Requirements →

Vulnerability Management FAQ

How quickly must I patch a vulnerability?

The CRA requires vulnerabilities to be addressed "without undue delay." For actively exploited vulnerabilities, this effectively means as fast as possible. The specific timeline may depend on severity and complexity, but the expectation is rapid response—typically days, not weeks.

What if a third-party component has a vulnerability?

As the manufacturer, you're responsible for your entire product—including third-party components. You must monitor dependencies (using SBOM) and distribute updated versions of your product with patched components. Work with your suppliers or update to patched versions.

Do I need a bug bounty program?

The CRA does not require a paid bug bounty program. However, you must have a way for researchers to report vulnerabilities (coordinated vulnerability disclosure). Whether you offer bounties is a business decision, but having a clear VDP is mandatory.

What testing is required?

The CRA requires "regular and effective" security testing. This includes vulnerability scanning, penetration testing, and code review as appropriate. The specific testing approach should be risk-based and documented as part of your security process.

Build Your Vulnerability Management Program

Start with our free VDP builder tool and SBOM generator guide.