Zurück zum Toolkit
Interaktives Tool

CRA Vulnerability Reporting Readiness

SME self-assessment for Article 14 CRA — actively exploited vulnerability reporting from 11 September 2026.

Original als ExcelENISA SRP FAQ · CRA Article 14 · NexTech.Law questionnaire v3
So funktioniert's

Wähle für jede Frage den Reifegrad (1 = informell, 5 = kontinuierlich verbessert). Die Auswertung — Domain-Mittelwerte, Gesamt-Score und Basis/Mittel/Fortgeschritten-Einordnung — aktualisiert sich live.

CRA Art. 14 · Meldezeitachse
Frühwarnung
innerhalb 24 h

Meldungsart, Hersteller, Produkt, Titel und betroffene Mitgliedstaaten.

72-Stunden-Meldung
innerhalb 72 h

Art der Schwachstelle und Ausnutzung, erste Bewertung, Gegenmaßnahmen, Nutzeraktionen.

Abschlussbericht
innerhalb 14 Tagen nach Verfügbarkeit einer Maßnahme

Vollständige Beschreibung, Schwere und Auswirkung, Angreiferinformationen, Sicherheitsupdate.

Nutzerkommunikation
zeitnah und verhältnismäßig

Betroffene Nutzer informieren, Mitigation und korrektive Maßnahmen erläutern.

Zwischenupdates
auf Anfrage des koordinierenden CSIRT

Status zu Schwachstelle, Ausnutzung und Behebung.

1.1 · Map products and dependencies

0/5 · 0.0
1.1

Have you identified every product with digital elements for which your organisation acts as the CRA manufacturer?

Basis · CRA Articles 2, 3 and 14 · Commission CRA FAQ §1Relevance · Mandatory foundation
1.2

Does the product register include products placed on the EU market before 11 December 2027?

Basis · CRA Article 69(3) · Commission CRA FAQ 5.3Relevance · Required for Article 14 reporting
1.3

For each product, can you identify affected versions, Member States where it is available, user groups and communication channels?

Basis · CRA Article 14(2), 14(7), 14(8) · ENISA SRP FAQ Q16Relevance · Required reporting data
1.4

Can you identify third-party and open-source components that may be the source of an actively exploited vulnerability in your product?

Basis · Commission CRA FAQ 5.4 · ENISA SRP FAQ Q14Relevance · Operationally necessary
1.5

Do you maintain a component inventory or SBOM sufficient to assess whether your product is affected?

Basis · CRA Annex I, Part II · ENISA SME Maturity ModelRelevance · Foundational for component analysis

2.2 · Receive and assess vulnerabilities

0/4 · 0.0
2.1

Is there a central, monitored channel for vulnerability reports from customers, researchers, suppliers and internal teams?

Basis · ENISA SME Maturity Model · Commission CRA FAQ 5.1Relevance · Define intake channel, acknowledgement and case register
2.2

Is every reported vulnerability logged, assigned an owner and triaged according to product impact and urgency?

Basis · CRA vulnerability-handling principles · ENISA SME Maturity ModelRelevance · Management readiness
2.3

Can the responsible team distinguish an actively exploited vulnerability from one that has only been discovered or responsibly disclosed?

Basis · CRA Article 3(42) · Commission CRA FAQ 5.2 · ENISA SRP FAQ Q11Relevance · Required reporting trigger
2.4

Is the time at which the manufacturer becomes aware documented immediately so that the 24-hour and 72-hour deadlines can be calculated?

Basis · CRA Article 14 · draft Commission CRA Guidance §9.1Relevance · Required deadline control

3.3 · Operate the reporting workflow

0/5 · 0.0
3.1

Are a primary reporter, backup reporter and management escalation contact formally assigned and reachable at short notice?

Basis · CRA Article 14 · ENISA SRP FAQ Q19Relevance · Assign named roles and ensure coverage
3.2

Can your organisation submit the 24-hour early warning with the minimum information available at that stage?

Basis · CRA Article 14(2)(a) · ENISA SRP FAQ Q7, Q16Relevance · Mandatory
3.3

Can your organisation submit the 72-hour notification with vulnerability, exploitation, initial assessment and mitigation information?

Basis · CRA Article 14(2)(b) · ENISA SRP FAQ Q7, Q16Relevance · Mandatory
3.4

Can the final report be completed within 14 days after a corrective or mitigating measure becomes available?

Basis · CRA Article 14(2)(c) · ENISA SRP FAQ Q7Relevance · Mandatory
3.5

Are submitted reports, supporting evidence, decisions and requested intermediate updates retained in one traceable case file?

Basis · CRA Article 14(6) · practical compliance evidenceRelevance · Strongly recommended

4.4 · Prepare SRP access

0/5 · 0.0
4.1

Have the nominated reporting representatives created EU Login accounts and tested access?

Basis · ENISA SRP FAQ Q9Relevance · Preparation required
4.2

Have you identified the CSIRT designated as coordinator based on your main establishment (or the applicable fallback for a non-EU manufacturer)?

Basis · CRA Article 14(7) · ENISA SRP FAQ Q18Relevance · Required routing information
4.3

Is the SRP access and registration procedure documented, including representative validation after first access?

Basis · ENISA SRP FAQ Q9Relevance · Validation runs in parallel — does not block submission
4.4

Have technical, legal, compliance and customer-support teams been trained on the reporting workflow?

Basis · ENISA SRP FAQ Q17 · operational readinessRelevance · Use ENISA training materials
4.5

Has the vulnerability-reporting workflow been tested in at least one tabletop or simulated exercise?

Basis · ENISA SME Maturity Model · operational readinessRelevance · Run at least one simulated exercise

5.5 · Remediate, communicate and improve

0/3 · 0.0
5.1

Is there a documented process to analyse, remediate, test and release corrective or mitigating measures for vulnerabilities?

Basis · CRA Annex I, Part II · ENISA SME Maturity ModelRelevance · Vulnerability-management readiness
5.2

Can impacted users be informed quickly about the vulnerability and the mitigation or corrective measures they should take?

Basis · CRA Article 14(8) · draft Commission CRA Guidance §9.1Relevance · Prepare approved user-notification templates
5.3

If the vulnerability originates in an integrated component and is exploitable in your product, can your team coordinate with the supplier while still submitting your own notification?

Basis · CRA Annex I, Part II · Commission CRA FAQ 5.4Relevance · Do not assume the component maker's report replaces yours

General guidance only. Not legal advice. Refer to the official CRA text, ENISA SRP FAQ and Commission CRA guidance for authoritative requirements.