A supplier or component manufacturer reports a vulnerability
Does it affect our product, a component we use or a released version?Connect product and version relevance with component and supplier information and your vulnerability process.
A component supplier reports a vulnerability. A product is approaching release. An external signal suggests a possible security incident. Or you need to determine which CRA requirements are relevant to your product and your role.
The key is to connect the specific product case, your economic-operator role, the current product and version state, and the actual trigger.
Connect product and version relevance with component and supplier information and your vulnerability process.
Establish whether the affected component and version are present in your product and what follows technically and operationally.
Connect first signal, awareness time, technical assessment, internal escalation and any possible reporting obligation.
Open items need to remain visible and have a controlled next step.
Changes can affect product scope, risk, vulnerability status, supplier evidence or technical documentation.
Missing information should remain visible and be requested deliberately.
The CRA combines cybersecurity requirements for products with obligations across the product lifecycle. Implementation therefore goes beyond technical documentation or a single conformity activity.
Define the product, variant and version and determine the relevant role.
Connect requirements with ownership, timing, completion criteria and expected evidence.
Tie assessments and measures to the actual product and version state.
Keep supplier and component information connected to product, vulnerability and evidence states.
Turn an external signal into a robust own assessment and response.
Connect intake, assessment, escalation, reporting decision and supporting evidence.
Keep evidence traceable to a specific product case and decision.
Keep open items and future reassessment triggers visible.
Mandatory notifications are submitted through the CRA Single Reporting Platform. The concrete reporting obligation must be assessed case by case.
SaaS, cloud, software or other service provider issue affecting your systems, data or processes.
Supplier and third-party cybersecurity (German page) →Product/version relevance, product security, vulnerability assessment, updates, evidence and possible reporting need to be connected.
View the CRA Praxis-Kit →The SP Services CRA Praxis-Kit supports the path from case orientation through operational work to release, evidence status, closure and reassessment.
View the CRA Praxis-Kit