Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

No. The EU Cyber Resilience Act (CRA) does not ban manual vulnerability triage or require automated triage software. It does require manufacturers to assess suspicious events immediately and, when they become reasonably certain that a qualifying event has occurred, meet staged reporting deadlines. That makes timely, documented triage more important—not obsolete.

What does the CRA require manufacturers to report?

The CRA is the EU’s product-security law for products with digital elements made available on the EU market. Its reporting duty is narrower than a rule to report every vulnerability: manufacturers must report an actively exploited vulnerability in their product, or a severe incident that affects the product’s security. The European Commission’s CRA reporting page describes these obligations and their deadlines.

For an incident, the relevant question is whether product security has been compromised. For a vulnerability, the trigger is active exploitation in the manufacturer’s product—not simply the existence of a flaw somewhere in the software ecosystem.

A reportable event is not the same as an alert

A vulnerability disclosure, scanner result, customer report or threat-intelligence alert can be a reason to investigate. It does not, by itself, establish that the CRA reporting threshold has been met. The Commission’s implementation guidance says manufacturers should assess suspicious events immediately. It describes awareness as arising when that initial assessment produces reasonable certainty that there is an actively exploited vulnerability or a severe incident that has compromised product security. This interpretation is set out in the Commission guidance reproduced at Official CRA Guidance; it is guidance on applying the regulation, not a verbatim quotation from the regulation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When do the reporting duties and deadlines apply?

The Commission says Article 14 reporting obligations for manufacturers apply from 11 September 2026. The main CRA cybersecurity requirements apply from 11 December 2027. According to the Commission’s implementation guidance, the reporting obligation applies from 11 September 2026 to in-scope products, including products placed on the market before 11 December 2027.

Open-source software stewards are a distinct case: the Commission says their Article 24(3) reporting obligations apply from 11 December 2027. Do not assume that every open-source maintainer has the same reporting start date as a manufacturer.

What are the CRA reporting deadlines?

The deadlines have different triggers. The 24-hour and 72-hour periods run from the manufacturer becoming aware of the reportable event; the final-report deadline depends on whether the event is an actively exploited vulnerability or a severe incident.

Report Deadline What starts the clock
Early warning Within 24 hours The manufacturer becomes aware of the reportable event.
Full notification Within 72 hours The manufacturer becomes aware of the reportable event.
Final report: actively exploited vulnerability No later than 14 days after a corrective measure is available Availability of the corrective measure.
Final report: severe incident Within one month The 72-hour notification.

These are deadlines stated by the European Commission, not estimates of how quickly companies currently respond. The final-report clocks should not be collapsed into a single rule: the vulnerability deadline is tied to a corrective measure becoming available, while the severe-incident deadline is tied to the earlier notification.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where does a manufacturer submit a report?

Manufacturers submit notifications through ENISA’s Single Reporting Platform (SRP). ENISA says it developed, operates and maintains the platform for CRA reporting. The Commission describes a notification addressed to the CSIRT in the country where the manufacturer has its main establishment and ordinarily made available to ENISA at the same time. The platform supports one submission to the relevant authorities.

The CRA Single Reporting Platform launched on 11 September 2026. That is the reporting channel—not a triage tool that decides whether an event is reportable. The manufacturer still needs to assess the event and make the threshold decision.

Does a vulnerability in a dependency have to be reported?

Not automatically. A flaw in an integrated component is reportable under this trigger if it is actively exploited in the manufacturer’s product. The Commission guidance says a component vulnerability that cannot be exploited in that product, or has not been exploited in it, does not meet that manufacturer’s mandatory reporting trigger. Other vulnerability-handling duties may still apply.

Example: a library flaw is disclosed

Suppose a widely used library has a newly disclosed vulnerability. The disclosure alone does not establish active exploitation in a particular device or application. The manufacturer needs product and version context to assess whether the component is present, whether the vulnerable code path can be reached in its product, and whether there is evidence of exploitation there. If the initial assessment reaches the Commission guidance’s awareness threshold for active exploitation in the product, the reporting clock applies.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This is why dependency intake and product-specific assessment matter even when an alert is not reportable. A useful record links the component and affected product versions to the evidence reviewed and the assessment outcome; it should not turn every upstream advisory into an automatic report.

Does this leave room for manual triage?

Yes. The CRA does not prescribe an automated triage product or prohibit a person from assessing an event. The Commission’s instruction to assess suspicious events immediately makes the decision and its timing consequential, but it does not specify whether people, software or a combination must perform that work.

Manual processes may be workable where intake is manageable and staff can quickly connect alerts to affected products, determine whether exploitation is credible in those products, and record when the reporting threshold was reached. Automation can assist with high-volume intake, asset and dependency matching, evidence capture and deadline tracking. It cannot remove the need for a defensible product-specific judgment, and the official sources do not establish that any particular tool is required or effective.

What to check in a triage workflow

  • Can it distinguish a vulnerability’s existence from evidence that it is actively exploited in the manufacturer’s product?
  • Does it record the initial assessment and the point at which there is reasonable certainty of a reportable event?
  • Can it track the 24-hour, 72-hour and applicable final-report clocks from their separate triggers?
  • Does it connect component alerts to product versions and whether the vulnerable component can be exploited in each product?
  • Can staff prepare a report for the correct CSIRT using the ENISA platform and coordinate proportionate user communications?

These are practical evaluation questions derived from the Commission’s reporting account and guidance, not an official CRA certification checklist or a ranking of products.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should manufacturers communicate to users?

The Commission guidance says a manufacturer should inform impacted users and, where appropriate, all users after becoming aware of a qualifying event. Disclosure should be risk-based and proportionate; the guidance does not say that every qualifying event must be announced publicly to everyone. The communication decision is separate from the reporting deadlines and should be handled as part of the incident response.

What should smaller manufacturers know?

The Commission recognizes that micro, small and medium-sized enterprises may lack the knowledge or expertise needed for implementation. Its CRA page for MSMEs, last updated 31 July 2026, lists EU-funded support projects including OCCTET, CONFIRMATE, CRACY and OSCRAT. These are support initiatives, not proof that a particular commercial triage product is necessary.

There is also an important timing distinction after a product’s support period ends. The Commission guidance says Article 14 reporting continues after the support period, while Annex I Part II vulnerability-handling duties are tied to the support period and have a different temporal reach. Manufacturers should not treat the end of support as automatically ending the reporting obligation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.