CRA Vulnerability Reporting Readiness
SME self-assessment for Article 14 CRA — actively exploited vulnerability reporting from 11 September 2026.
Wähle für jede Frage den Reifegrad (1 = informell, 5 = kontinuierlich verbessert). Die Auswertung — Domain-Mittelwerte, Gesamt-Score und Basis/Mittel/Fortgeschritten-Einordnung — aktualisiert sich live.
Meldungsart, Hersteller, Produkt, Titel und betroffene Mitgliedstaaten.
Art der Schwachstelle und Ausnutzung, erste Bewertung, Gegenmaßnahmen, Nutzeraktionen.
Vollständige Beschreibung, Schwere und Auswirkung, Angreiferinformationen, Sicherheitsupdate.
Betroffene Nutzer informieren, Mitigation und korrektive Maßnahmen erläutern.
Status zu Schwachstelle, Ausnutzung und Behebung.
1.1 · Map products and dependencies
Have you identified every product with digital elements for which your organisation acts as the CRA manufacturer?
Does the product register include products placed on the EU market before 11 December 2027?
For each product, can you identify affected versions, Member States where it is available, user groups and communication channels?
Can you identify third-party and open-source components that may be the source of an actively exploited vulnerability in your product?
Do you maintain a component inventory or SBOM sufficient to assess whether your product is affected?
2.2 · Receive and assess vulnerabilities
Is there a central, monitored channel for vulnerability reports from customers, researchers, suppliers and internal teams?
Is every reported vulnerability logged, assigned an owner and triaged according to product impact and urgency?
Can the responsible team distinguish an actively exploited vulnerability from one that has only been discovered or responsibly disclosed?
Is the time at which the manufacturer becomes aware documented immediately so that the 24-hour and 72-hour deadlines can be calculated?
3.3 · Operate the reporting workflow
Are a primary reporter, backup reporter and management escalation contact formally assigned and reachable at short notice?
Can your organisation submit the 24-hour early warning with the minimum information available at that stage?
Can your organisation submit the 72-hour notification with vulnerability, exploitation, initial assessment and mitigation information?
Can the final report be completed within 14 days after a corrective or mitigating measure becomes available?
Are submitted reports, supporting evidence, decisions and requested intermediate updates retained in one traceable case file?
4.4 · Prepare SRP access
Have the nominated reporting representatives created EU Login accounts and tested access?
Have you identified the CSIRT designated as coordinator based on your main establishment (or the applicable fallback for a non-EU manufacturer)?
Is the SRP access and registration procedure documented, including representative validation after first access?
Have technical, legal, compliance and customer-support teams been trained on the reporting workflow?
Has the vulnerability-reporting workflow been tested in at least one tabletop or simulated exercise?
5.5 · Remediate, communicate and improve
Is there a documented process to analyse, remediate, test and release corrective or mitigating measures for vulnerabilities?
Can impacted users be informed quickly about the vulnerability and the mitigation or corrective measures they should take?
If the vulnerability originates in an integrated component and is exploitable in your product, can your team coordinate with the supplier while still submitting your own notification?
General guidance only. Not legal advice. Refer to the official CRA text, ENISA SRP FAQ and Commission CRA guidance for authoritative requirements.