BizNavi HubSign in

Regulation (EU) 2024/2847

CRA vulnerability handling evidence

See whether the support-period records for inventory, SBOM, intake, remediation, testing, and disclosure can be produced. This page does not decide a reporting deadline.

What this screen checks

This screen looks only at evidence that a manufacturer is handling vulnerabilities during the support period. It asks for an inventory, a component list, an SBOM, intake and triage, remediation and security updates, testing, disclosure of fixed issues, and a technical file. It is separate from CRA readiness, CRA reporting, substantial-modification review, and the support-period planner.

SBOM and components

Annex I Part II asks the manufacturer to identify and document vulnerabilities and components, and to keep an SBOM that covers at least the top-level dependencies. A partial SBOM stays an evidence gap on this page. The page does not name products or components.

Vulnerability-handling records

The manufacturer systematically documents relevant cybersecurity aspects, including vulnerabilities it becomes aware of and relevant information from third parties. During the support period, vulnerabilities in the product, including its components, are handled effectively. Missing intake, inventory, or triage records are a process gap. Missing evidence is not treated here as a legal violation.

Security-update records

Addressed vulnerabilities are remediated without delay, and security updates are provided where required. Where technically feasible, security updates are separated from functionality updates. If separation is not feasible, record that feasibility judgment. That judgment is not treated as a failure by itself.

Testing and review records

Effective and regular security tests and reviews are part of the handling record. A missing test record is its own evidence gap. This page does not score how severe any issue is.

Fixed-issue disclosure

After a security update is available, information about fixed vulnerabilities is disclosed, including the affected product, the impact, the severity, and remediation guidance, unless a justified security exception applies. A delayed disclosure needs a documented reason. If delayed disclosure is not used, that record is not required.

Illustrative examples

  • The other records are present and the SBOM is missing: SBOM or component evidence gap.
  • The SBOM is present and remediation records are absent: remediation or update evidence gap.
  • The processes are present and fixed-issue disclosure is missing: disclosure evidence gap.
  • The evidence set is substantially present. That does not establish CRA compliance or product security.

Limits

This does not establish CRA compliance or product security. There is no numeric score. The tool does not invent extra duties, does not accept CVE numbers or exploit detail, and does not decide whether a change is a substantial modification or when a report is due. Later Commission guidance is a reason to update the ruleset by hand.

Official sources