It is a continuous process with records, not a periodic scan. The record per vulnerability is the evidence.
The requirements
| Part II point | What the manufacturer must do |
|---|---|
| (1) | Identify and document vulnerabilities and components, with an SBOM |
| (2) | Address and remediate vulnerabilities without delay, providing security updates. Where technically feasible, security updates are separate from functionality updates |
| (3) | Apply effective and regular tests and reviews |
| (4) | After an update is available, publish information on fixed vulnerabilities |
| (5) | Put in place and enforce a coordinated vulnerability disclosure policy |
| (6) | Facilitate information sharing, including a contact address |
| (7) | Provide mechanisms to distribute updates securely, automatically where applicable |
| (8) | Disseminate updates without delay and free of charge, with advisory messages |
Article 13(6) adds that when a vulnerability is found in a component, including an open-source component, the manufacturer must report it to whoever maintains the component. Article 13(8) requires the handling to last for the support period, which must be at least five years unless the product is expected to be used for less.
Tooling
Continuous vulnerability monitoring usually combines SBOM-based component data with a vulnerability management platform. CRAprepared helps choose and introduce this tooling; see the Slovenian pages on vulnerability management solutions and SBOM management. A tool supports the process. Compliance needs organisational, technical and documentation measures together.
Using CVSS alone to prioritise. A medium-severity vulnerability that is actively exploited matters more for CRA reporting than a high one in unreachable code.
We help manufacturers turn this requirement into a process and evidence.
Related guidance
- Cyber Resilience Act (CRA): what it is and what it requires
- CRA SBOM requirements: what is actually required?
- CRA reporting obligations: 24 hours, 72 hours and final report
This guidance explains the regulation and gives practical recommendations. It is not legal advice. Regulatory facts and recommendations are labelled separately. See our editorial policy (Slovenian): editorial policy.