Exploited vulnerabilities

What can be missing from a CRA vulnerability final report?

Submission status and content completeness must be checked separately. A receipt cannot establish that severity, impact, exploitation information and measure details were included.

Prepared by CRA Operations · Updated 2026-09-13 · Hypothetical worked examples

The situation

A manufacturer marks every reporting stage as submitted on time. During review, the team cannot confirm that the final report describes the vulnerability’s severity and impact. That missing evidence must remain visible even though the submission timestamps appear satisfactory.

Facts that change the answer

  • Does the final report describe the vulnerability, severity and impact?
  • Is available exploitation information retained?
  • Are measure details, recipients and user communication recorded?

Compare the worked results

These examples use the published assessment with the assumptions shown below. Change the facts in your own assessment before relying on its result.

Submission recorded; severity and impact evidence missing

Hypothetical example 1

Assessment resultreporting deadline or content gap

Escalate the missed, uncertain, or incomplete Article 14 notification step immediately and preserve the actual submission timestamps.(CRA Article 14(2), (7) and (8))

Key facts in this example
The final report describes the vulnerability, including severity and impact
No
All recorded assumptions (18)
Affected product with digital elements
Hypothetical example product
Reporting role
manufacturer
Timestamp when the organisation became aware of the vulnerability
2026-09-11T09:00:00Z
Evidence that a malicious actor is exploiting the vulnerability in a system without the system owner’s permission
confirmed
24-hour early-warning status
submitted within 24 hours
72-hour vulnerability-notification status
submitted within 72 hours
The notification records, where applicable, Member States where the product is known to have been made available
Yes
The 72-hour notification records available product information and the general nature of the exploit and vulnerability
Yes
A corrective or mitigating measure is available
Yes
Date the corrective or mitigating measure became available
2026-09-12
Corrective or mitigating measures taken, and measures users can take, are recorded
Yes
The notification records how sensitive the submitted information is, where applicable
Yes
Final-report status within 14 days after a corrective or mitigating measure became available
submitted within 14 days
The final report describes the vulnerability, including severity and impact
No
Available information about malicious exploitation and relevant threat actors is recorded
Yes
The final report gives details of the security update or other corrective or mitigating measures
Yes
Impacted users were informed without undue delay, including necessary risk-mitigation or corrective measures
Yes
Submission to the designated coordinating CSIRT and ENISA is confirmed
Yes

All notification stages and content recorded

Hypothetical example 2

Assessment resultnotification record complete
Key facts in this example
The final report describes the vulnerability, including severity and impact
Yes
All recorded assumptions (18)
Affected product with digital elements
Hypothetical example product
Reporting role
manufacturer
Timestamp when the organisation became aware of the vulnerability
2026-09-11T09:00:00Z
Evidence that a malicious actor is exploiting the vulnerability in a system without the system owner’s permission
confirmed
24-hour early-warning status
submitted within 24 hours
72-hour vulnerability-notification status
submitted within 72 hours
The notification records, where applicable, Member States where the product is known to have been made available
Yes
The 72-hour notification records available product information and the general nature of the exploit and vulnerability
Yes
A corrective or mitigating measure is available
Yes
Date the corrective or mitigating measure became available
2026-09-12
Corrective or mitigating measures taken, and measures users can take, are recorded
Yes
The notification records how sensitive the submitted information is, where applicable
Yes
Final-report status within 14 days after a corrective or mitigating measure became available
submitted within 14 days
The final report describes the vulnerability, including severity and impact
Yes
Available information about malicious exploitation and relevant threat actors is recorded
Yes
The final report gives details of the security update or other corrective or mitigating measures
Yes
Impacted users were informed without undue delay, including necessary risk-mitigation or corrective measures
Yes
Submission to the designated coordinating CSIRT and ENISA is confirmed
Yes

Evaluated on 2026-09-13 using EU Cyber Resilience Act actively exploited vulnerability notification record, version 2026.09.02. A completed example is not a customer Record or a declaration of conformity.

Evidence to keep

  • Submitted final report and authority receipt
  • Severity, impact and exploitation references
  • Corrective-measure details and user notices

Keep source artifacts in their controlled systems and record their references, responsible owner and review date with the decision.

Your next step

Reconcile the submitted content with the evidence checklist. Preserve corrections and later communications alongside the original receipt.

Choose your real product or vulnerability case in the workspace. The selected assessment will be highlighted; example answers are not copied into your record.

Sources and application dates

Manufacturer reporting applies from 11 September 2026. Broader product requirements apply from 11 December 2027; these product-readiness examples support preparation. Open-source-steward obligations have their own application date.

These examples structure a decision and do not replace the Regulation, official guidance or product-specific professional advice. Not lawyer-reviewed.

Related situations