The deadline starts before certainty arrives
From 11 September 2026, Article 14 of the Cyber Resilience Act will require manufacturers to report actively exploited vulnerabilities through an early warning without undue delay and, in any event, within 24 hours after becoming aware. A fuller vulnerability notification follows within 72 hours, with a final report later in the process.
Operationally, those clocks expose weak product traceability. A manufacturer may know that a component appears in an SBOM but still not know which versions are deployed, whether the vulnerable function is reachable, which supplier can validate the finding or who is authorised to notify.
The bottleneck is therefore not the reporting form. It is the time required to turn a vulnerability signal into an evidence-backed scope and decision.
The reporting clock exposes the dependencies required to turn incomplete technical evidence into a defensible regulatory decision within hours.
Can the manufacturer identify affected products and make an owned notification decision before supplier certainty is complete?
SBOM and VEX are inputs, not the decision itself
CISA’s VEX guidance frames VEX as a way for suppliers to communicate whether a known vulnerability actually affects a product. That can dramatically reduce noise, but only if the statement is supported by product-specific technical reasoning and remains current as versions and configurations change.
NIST SSDF reinforces the lifecycle discipline needed around software components, provenance and vulnerability response. For a manufacturer, the practical capability is an evidence graph linking product, software version, component, exploitability assessment, supplier owner, mitigation and customer exposure.
The strongest CRA process therefore predefines escalation authority and minimum evidence thresholds. Teams should know what they can state at 24 hours, what must be confirmed by 72 hours, and which uncertainty must remain explicit rather than being hidden behind a generic VEX status.
- Maintain product-to-component-to-version traceability.
- Define who owns the first exploitability assessment.
- Set supplier response expectations before incidents.
- Record uncertainty and decision rationale at 24 and 72 hours.
- Pre-authorise regulatory escalation roles and backups.
