Cyber Resilience Act decision examples
CRA exploited vulnerabilities
Separate a known weakness from active exploitation and prepare the reporting sequence. Compare worked examples and the evidence behind each CRA assessment.
Which reporting action comes next?
Open a situation to compare the relevant facts, worked results and evidence to retain.
Does a CVE alone trigger CRA vulnerability reporting?
A CVE identifies a vulnerability; it does not alone establish active exploitation. Preserve evidence of whether a malicious actor is exploiting the weakness without the owner’s permission.
View facts and examplesWhen does the CRA vulnerability final-report clock start?
The vulnerability final report is tied to availability of a corrective or mitigating measure. It should not be calculated as a fixed interval from the initial awareness timestamp.
View facts and examplesWhat can be missing from a CRA vulnerability final report?
Submission status and content completeness must be checked separately. A receipt cannot establish that severity, impact, exploitation information and measure details were included.
View facts and examplesHow to use these examples
The situations are hypothetical and use explicitly recorded assumptions. They explain a decision path, not a conclusion about your own product. Reporting obligations for manufacturers apply from 11 September 2026; broader product requirements apply from 11 December 2027.
Product-readiness examples support preparation for those broader requirements. A readiness result does not declare conformity. Primary sources and the assessment version are provided on each situation page.