Your software vendor reports a vulnerability
Does the notification affect a version, component or service that we actually use?Clarify what is affected, where it is used, what is confirmed and what is still missing.
A supplier reports a vulnerability. A cloud provider informs you about a cyber incident. A SaaS provider changes a subcontractor. A critical supplier cannot provide the requested security evidence.
The event happens outside your company. Its effects can still reach your systems, processes, products, data or customers.
Clarify what is affected, where it is used, what is confirmed and what is still missing.
An incident at a provider should not simply be filed away as the provider’s problem.
Certificates and self-assessments can help, but do not answer every specific question.
Link components and versions, known vulnerabilities and the current assessment status.
Changes can create new risks, information needs or reassessment triggers.
Cybersecurity and resilience meet where external dependency becomes a single point of failure.
Record what was reported, by whom and when.
Identify the supplier, service, component, version and your actual use.
Keep assumptions and missing information visible.
Route the case into the right internal assessment and decision process.
For SaaS, cloud, software or external service provider situations, assess the impact on your own systems, processes and data.
Open the 7-question Quick Guide →When the component is part of a product with digital elements, product and version relevance, vulnerability assessment and possible reporting need to be connected.
Go to the Cyber Resilience Act →The Supplier Cybersecurity Practice Kit supports the path from criticality and supplier assessment through contractual security requirements, SBOM/VEX and vulnerabilities to incidents, monitoring, measures, approvals and evidence.

Questions for the first steps after an external security notification.
The free Quick Guide structures the initial intake: notification, own dependency, confirmed facts, information gaps, internal ownership and the next review point.
It covers cyber risks arising from suppliers, software vendors, cloud and SaaS services and other external service providers.
Clarify the supplier, service, component and version, your actual use, confirmed facts, missing information, ownership and the next review point.
No. First determine which data, services, processes or systems may be affected and whether this triggers your own process.
When affected software, firmware or a component is part of your own product with digital elements, the CRA product perspective may also be relevant.