A strong CRA security advisory tells customers whether they are affected, what the vulnerability means, which corrected release is available and what they need to do. It should be specific enough to support remediation without turning the notice into a marketing release note or a substitute for Article 14 regulatory reporting.
Publish Fixed-Vulnerability Information After a Security Update Is Available
Annex I Part II point 4 requires manufacturers, once a security update has been made available, to share and publicly disclose information about fixed vulnerabilities. The customer advisory should therefore be connected to actual remediation availability rather than describing a fixed issue without identifying how affected users can obtain the correction.
- Connect the advisory to an available fix.
- Identify the corrected release.
- Keep vulnerability and update records linked.
- Publish through a durable security channel.
Describe the Fixed Vulnerability
Point 4 requires a description of the fixed vulnerability. The description should be specific enough that users and security teams understand the nature of the issue without including unnecessary exploit detail that would create additional risk. The level of technical detail can vary by product and audience.
- Describe the affected security condition.
- Use clear technical language.
- Avoid unnecessary exploitation detail.
- Keep the description consistent with internal records.
Identify Affected Products and Versions
Point 4 requires information allowing users to identify the affected product. Where the product has several branches or hardware revisions, the advisory should identify affected versions precisely. A broad product-family name can be insufficient if some versions are fixed, unaffected or outside the vulnerable code path.
- Affected products.
- Affected versions or builds.
- Relevant hardware revisions where needed.
- Corrected versions.
Explain Impact and Severity
Annex I Part II point 4 requires the impacts of the vulnerabilities and their severity. The advisory should explain the security consequence in user-relevant terms and use a severity classification consistent with the manufacturer's assessment. A severity label alone is not enough if users cannot understand what the vulnerability can affect.
- State severity.
- Explain confidentiality, integrity or availability impact where relevant.
- Explain important exploitation prerequisites.
- Use consistent severity terminology.
Provide Clear Remediation Information
Point 4 requires clear and accessible information helping users remediate the fixed vulnerability. The advisory should identify the security update, fixed version or other permanent remediation and explain where users can obtain it. Temporary mitigations should be labelled separately so users do not mistake them for a complete fix.
- Identify the security update.
- Identify fixed versions.
- Explain installation or upgrade steps.
- Separate mitigation from permanent remediation.
Include the Potential Action Users Need to Take
Annex I Part II point 8 requires advisory messages accompanying security updates to include relevant information, including potential action to be taken. Customer advisories should therefore state whether users need to install an update, restart a system, change a configuration, rotate credentials or take another security action.
- State required user action.
- Identify prerequisites.
- Explain timing where urgency matters.
- Keep instructions version-specific.
Use Justified Disclosure Delay Only for Security Reasons
Annex I Part II point 4 allows public disclosure to be delayed in duly justified cases where the security risks of publication outweigh the security benefits until users have had the possibility to apply the relevant patch. The exception should be documented and should not be treated as a general commercial option to avoid publishing uncomfortable security information.
- Assess publication risk.
- Document the security justification.
- Give users an opportunity to patch.
- Publish when the security basis for delay no longer applies.
Keep Customer Advisories Separate From Article 14 Reporting
A customer advisory serves users, while Article 14 reporting serves the CRA regulatory notification process. The two can share factual information but one does not replace the other. Manufacturers should coordinate affected-version, severity and remediation data while keeping the channels and legal purposes distinct.
- Do not use the advisory as the regulatory notification.
- Do not assume regulatory reporting informs customers.
- Keep facts consistent across both processes.
- Coordinate timing where appropriate.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.