CRApreparedContact us

Cyber Resilience Act

CRA vulnerability management requirements

The CRA requires manufacturers to handle vulnerabilities effectively for the whole support period, following Annex I Part II: identify and document them, remediate without delay, test regularly, publish information about fixed vulnerabilities, run a coordinated vulnerability disclosure policy and distribute security updates securely.

Written by: CRAprepared teamExpert: Dejan TropLast reviewed: 2 min read
In short

It is a continuous process with records, not a periodic scan. The record per vulnerability is the evidence.

The requirements

Part II pointWhat the manufacturer must do
(1)Identify and document vulnerabilities and components, with an SBOM
(2)Address and remediate vulnerabilities without delay, providing security updates. Where technically feasible, security updates are separate from functionality updates
(3)Apply effective and regular tests and reviews
(4)After an update is available, publish information on fixed vulnerabilities
(5)Put in place and enforce a coordinated vulnerability disclosure policy
(6)Facilitate information sharing, including a contact address
(7)Provide mechanisms to distribute updates securely, automatically where applicable
(8)Disseminate updates without delay and free of charge, with advisory messages

Article 13(6) adds that when a vulnerability is found in a component, including an open-source component, the manufacturer must report it to whoever maintains the component. Article 13(8) requires the handling to last for the support period, which must be at least five years unless the product is expected to be used for less.

Tooling

Continuous vulnerability monitoring usually combines SBOM-based component data with a vulnerability management platform. CRAprepared helps choose and introduce this tooling; see the Slovenian pages on vulnerability management solutions and SBOM management. A tool supports the process. Compliance needs organisational, technical and documentation measures together.

Common mistake

Using CVSS alone to prioritise. A medium-severity vulnerability that is actively exploited matters more for CRA reporting than a high one in unreachable code.

Relevant service

We help manufacturers turn this requirement into a process and evidence.

See the service (Slovenian)

Related guidance

Written by: CRAprepared teamExpert: Dejan Trop, Cybersecurity strategistLast reviewed: Editorial policy

This guidance explains the regulation and gives practical recommendations. It is not legal advice. Regulatory facts and recommendations are labelled separately. See our editorial policy (Slovenian): editorial policy.

Will your product be CRA prepared?

CRA reporting obligations have applied since 11 September 2026. Most CRA requirements apply from 11 December 2027. We work with manufacturers in Slovenia and across the EU. Write to us in English or Slovenian.