Independent information resource Product security · EU CRA
Post-market / 08

Vulnerability handling and coordinated response

A workflow for intake, triage, remediation, updates, disclosure and applicable reporting.

IN BRIEF

Vulnerability handling is an ongoing manufacturer responsibility. Annex I Part II addresses effective handling over the support period; Article 14 sets notification duties for specified exploited vulnerabilities and severe incidents.

OPERATIONAL RESPONSE LOOP
01IntakeRecord the report
02AssessAffected products
03RemediateVerify correction
04CommunicateUpdate and document

Check Article 14 separately for notification triggers and timing.

01 / 03

A practical response loop

Use this as an operational model, not a verbatim legal sequence.

  • Receive and record reports, including third-party component issues.
  • Assess impact, exploitability and affected versions.
  • Develop and verify a correction.
  • Coordinate disclosure and distribute security updates.
  • Document decisions and revisit product risk.
02 / 03

Separate reporting from disclosure

From 11 September 2026, manufacturers must notify actively exploited vulnerabilities and severe incidents affecting product security under Article 14. The Commission describes an early warning within 24 hours and a main notification within 72 hours of awareness, with distinct final-report rules. Check the full legal conditions and the Single Reporting Platform before acting.

03 / 03

Make support visible

The manufacturer determines a support period and communicates its end date at purchase. Vulnerability processes and updates should be planned across that period.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.