Cyber Resilience Act decision examples
CRA severe incidents
Assess security impact and preserve the evidence for each notification stage. Compare worked examples and the evidence behind each CRA assessment.
Does the incident meet the reporting threshold?
Open a situation to compare the relevant facts, worked results and evidence to retain.
Is a service outage a severe security incident under the CRA?
The CRA threshold concerns the product’s security effects, including its ability to protect important data or functions and the introduction of malicious code. An outage label alone is insufficient.
View facts and examplesWhat should the CRA severe-incident final report establish?
The final report needs the incident’s severity and impact, threat type or likely root cause, and mitigation details. Its one-month limit runs from the actual incident notification.
View facts and examplesHow to use these examples
The situations are hypothetical and use explicitly recorded assumptions. They explain a decision path, not a conclusion about your own product. Reporting obligations for manufacturers apply from 11 September 2026; broader product requirements apply from 11 December 2027.
Product-readiness examples support preparation for those broader requirements. A readiness result does not declare conformity. Primary sources and the assessment version are provided on each situation page.