CRA and Vulnerability Disclosure: what the Cyber Resilience Act requires from companies
By Kike Gandia · Co-Founder & CEO, OSCP
The Cyber Resilience Act (CRA) introduces specific vulnerability disclosure obligations for manufacturers and distributors of products with digital elements in the EU. This guide breaks down what the CRA requires, the notification deadlines and how to prepare your vulnerability management process to comply before 2027.
The CRA in context: why it mandates vulnerability disclosure
The CRA is the European cybersecurity regulation for products with digital elements — from IoT devices to enterprise software. It affects manufacturers, importers and distributors that place digital products on the EU market.
Which products fall under these disclosure obligations
Connected hardware, embedded software, mobile applications, enterprise software and any product capable of connecting to networks or devices. Products already covered by specific sector regulations (aviation, automotive, healthcare) are excluded.
When these disclosure obligations become enforceable
The CRA entered into force in October 2024. The reporting obligations for actively exploited vulnerabilities apply from August 2026. The regulation applies in full from December 2027. The preparation window is narrow.
Disclosure obligations under the CRA
The CRA requires actively exploited vulnerabilities to be notified to ENISA within a maximum of 24 hours of detection. This is one of the most demanding obligations in the regulation and requires highly agile internal processes.
The 24-hour deadline for exploited vulnerabilities
When you detect (or receive a report of) a vulnerability that is being actively exploited, you have 24 hours to notify ENISA and the national CSIRT. This means having an extremely agile triage process that identifies the exploitation status in minutes, not days.
The 72-hour deadline for initial notification
For any significant vulnerability (not only exploited ones), the CRA requires an initial notification to ENISA within 72 hours. This notification must include a description, estimated impact and available mitigations. The CRA adopts the Coordinated Vulnerability Disclosure (CVD) model as the recommended standard for receiving and managing external reports.
How to prepare your vulnerability management process for the CRA
Complying with the CRA takes more than a written policy. You need a public channel to receive reports (security@, a secure form or a formal VDP), a triage process that carries out technical validation and determines the exploitation status within hours, and the integrations needed to notify ENISA in the required format.
CRA vs NIS2: differences in disclosure obligations
NIS2 and the CRA overlap in some respects but have distinct scopes. NIS2 focuses on operators of essential and important services. The CRA focuses on manufacturers of digital products. Many companies are subject to both regulations at the same time.
What happens if you fail to notify: the disclosure penalty regime
Fines for non-compliance with the CRA are significant: up to 15 million euros or 2.5% of annual global turnover for the most serious breaches. In addition, the European Commission can restrict or ban the product from being placed on the European single market.
FAQ
Does the CRA require me to set up a bug bounty programme?
Not directly, but it does require you to have a vulnerability reporting channel and a CVD process. A bug bounty programme is one way to meet this obligation while also attracting researchers who help you discover vulnerabilities before they are exploited.
When do I have to start complying with the CRA's disclosure obligations?
The reporting obligations for actively exploited vulnerabilities apply from August 2026. The regulation applies in full from December 2027. However, preparing internal processes takes months, so you should start now.
What happens if I receive a report of an exploited vulnerability outside working hours?
The CRA's 24-hour deadline does not distinguish between working and non-working hours. You need an on-call process or an external team that can receive, assess and notify the report at any time. This is one of the strongest arguments for outsourcing triage.
Related service
Vulnerability Disclosure Program management
Related content
- NIS2 and Vulnerability Disclosure
- What is a VDP?
- What is the Cyber Resilience Act
- CRA timeline and deadlines
- CRA requirements for manufacturers
- CRA fines and penalties
- CRA compliance consulting