CYBERSECURITY VULNERABILITY
& INCIDENT REPORTING

Under the CRA, manufacturers are
required to notify two specific types of events:

Actively Exploited Vulnerabilities
Vulnerabilities in products with digital elements for which there is reliable evidence that they have been exploited by a malicious actor;
Severe Incidents
Incidents having a severe impact on the security of a product with digital elements (e.g., compromising its availability, authenticity, integrity, or confidentiality). The criteria for severity are set out in Art. 14(5).