Vulnerability Management under the Cyber Resilience Act

The EU Cyber Resilience Act (CRA) is changing what cybersecurity responsibility looks like for manufacturers of products with digital elements. Security can no longer be treated as something that ends when a product is shipped. Manufacturers are expected to identify, manage, remediate and communicate vulnerabilities throughout the product's expected support period.

For manufacturers preparing for CRA compliance, the real challenge is operational readiness. Having a vulnerability policy on paper is not enough. Teams need a repeatable process that connects vulnerability discovery, triage, CVE assessment, remediation, patch development, disclosure and regulatory reporting.

This becomes particularly important from 11 September 2026, when CRA reporting obligations begin. Manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements.

Establish a Structured Vulnerability Handling Process

A CRA-ready program should define what happens from the moment a vulnerability is discovered until it is fully remediated and closed.

Manufacturers should establish clear procedures for:

  • Vulnerability intake and identification
  • Risk assessment and prioritisation
  • Assignment of ownership
  • Technical investigation
  • Remediation and mitigation
  • Patch validation
  • Customer communication
  • Documentation and closure

The process should cover vulnerabilities discovered internally, reported by researchers, identified through monitoring, or inherited through third-party and open-source components.

Importantly, CRA vulnerability handling applies to the product as a whole, including integrated components. Manufacturers are expected to exercise appropriate due diligence when incorporating third-party and open-source software.

Build a Coordinated Vulnerability Disclosure (CVD) Program

Researchers, customers and security professionals need a clear and trusted way to report vulnerabilities.

A Coordinated Vulnerability Disclosure (CVD) policy gives external parties a defined route for reporting security issues while allowing the manufacturer to investigate and remediate them before detailed information becomes public.

Under the CRA, manufacturers should establish a structured CVD policy that facilitates vulnerability reporting either directly or, where applicable, through designated CSIRTs.

A practical CVD process should define:

  • Where vulnerabilities should be reported
  • Information researchers should provide
  • How reports are acknowledged
  • Severity and impact assessment
  • Communication timelines
  • Remediation coordination
  • Disclosure and publication procedures

This creates a more predictable relationship between the manufacturer and the security community—and reduces the risk of vulnerabilities being disclosed before fixes are ready.

Create a Dedicated Security Response Team

Vulnerability management becomes difficult when responsibility is spread across disconnected teams.

Manufacturers should establish a security response function with clearly defined roles across cybersecurity, product engineering, software development, quality assurance, legal and compliance.

The team should be able to answer three questions quickly:

Who owns the vulnerability? What is its impact? What needs to happen next?

A mature response team can also maintain escalation paths for critical vulnerabilities and incidents, ensuring that technical findings reach management and regulatory stakeholders when required.

Continuously Monitor for New Vulnerabilities

Vulnerability management cannot operate as a one-time security assessment. Manufacturers need ongoing monitoring of:

  • Security advisories
  • Vulnerability databases
  • Vendor security notifications
  • Product security reports
  • Threat intelligence
  • Open-source project advisories
  • Newly published CVEs
  • Reports from customers and researchers

The objective is to identify whether a newly disclosed vulnerability affects products already in the field—not simply whether the vulnerability exists somewhere in the industry.

Regular monitoring should feed directly into the organisation’s vulnerability register and risk assessment process.

Monitor Third-Party Dependencies

Modern products rarely consist entirely of internally developed code. They often include operating systems, libraries, frameworks, firmware, open-source packages and commercial components.

This creates an important CRA consideration: your product's security can depend on someone else's software.

Manufacturers should maintain visibility into their software and component inventory, ideally supported by a Software Bill of Materials (SBOM). When a vulnerability is announced, teams should be able to quickly determine:

Is the affected component used in our product? Which versions are affected? Which product releases contain it?

The CRA specifically expects manufacturers to exercise due diligence when integrating third-party components, including checking vulnerability information and security update practices where appropriate.

6. Strengthen CVE Management

CVE management should be connected to product-level risk—not treated as a simple database exercise.

When a new CVE is published, the security team should determine:

  1. Whether the affected component is present.
  2. Which product versions are impacted.
  3. Whether the vulnerability is exploitable in the product's actual configuration.
  4. The potential business and security impact.
  5. Whether a patch, workaround or mitigation exists.
  6. Whether regulatory reporting is required.

This approach helps manufacturers avoid both underestimating vulnerabilities and wasting resources on issues that have little practical impact.

Establish a Repeatable Patch Development Workflow

Finding a vulnerability is only the beginning. The next challenge is producing and delivering a reliable fix.

A CRA-ready patch workflow should move through defined stages:

01Identify
02Triage
03Develop
04Test
05Validate
06Release
07Communicate
08Monitor

For critical vulnerabilities, organisations should have an accelerated process that allows engineering and security teams to work together without bypassing essential quality controls.

Testing should verify that the fix resolves the vulnerability without introducing new security or functional problems. Once released, manufacturers should also monitor whether customers have successfully adopted the remediation.

Prepare for CRA Reporting Obligations

This is where operational readiness becomes particularly important.

From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents through the CRA Single Reporting Platform. The initial early warning for an actively exploited vulnerability is due within 24 hours of becoming aware of it, followed by a vulnerability notification within 72 hours. A final report is generally required no later than 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability.

These deadlines leave little room for manual confusion.

Manufacturers should therefore establish reporting playbooks before an incident occurs. The process should define:

  • Who determines whether an event is reportable
  • Who approves regulatory notifications
  • Who gathers technical information
  • Who communicates with authorities
  • How reporting deadlines are tracked
  • How corrective measures are documented
  • How customer communications are coordinated

The CRA Single Reporting Platform is intended to provide the mechanism for these notifications, with information routed to the relevant CSIRT and made simultaneously available to ENISA under the applicable process.

Turning CRA Requirements into an Operational Program

CRA compliance is ultimately less about having another cybersecurity document and more about building an organisation that can respond consistently when vulnerabilities emerge.

A strong vulnerability management program connects people, processes, technology and governance. It provides visibility across products and dependencies, gives researchers a responsible reporting channel, enables rapid technical response and ensures regulatory obligations are not missed.

How Ascenten Technologies Helps Manufacturers Establish Vulnerability Management Programs

At Ascenten Technologies, vulnerability management can be approached as an operational cybersecurity capability rather than a compliance checkbox. The focus is on helping product manufacturers establish structured processes for vulnerability identification, assessment, remediation, third-party dependency monitoring, coordinated disclosure and incident response.

With the right processes in place before September 2026, manufacturers can move from reactive vulnerability handling to a more controlled and measurable approach to CRA readiness.

Ready to strengthen your CRA vulnerability management process? Connect with Ascenten Technologies to build a vulnerability management program aligned with your product security and EU compliance requirements.

FAQs
CRA reporting obligations for actively exploited vulnerabilities and severe incidents begin on 11 September 2026.
Yes. CRA vulnerability handling applies to products as a whole, including integrated components, and manufacturers are expected to exercise appropriate due diligence regarding third-party and open-source components.
The CRA requires an early warning within 24 hours of the manufacturer becoming aware of an actively exploited vulnerability, followed by further notification within 72 hours.

Contact Us

We would really like to hear from you and answer any questions. Please email us at info1@ascenten.net
or call us on

India Landline: +91-79-2646 4646

India Mobile: +91-89800 00973

refresh