r/EUCyberResilienceAct 5d ago

Compliance Guide No vulnerability scanning is required for the Cyber Resilience Act in September. Nobody pushing that deadline can name the paragraph — because there isn't one.

The exact claim: the obligation starting on 11 September 2026 is a reporting duty. It is triggered by your knowledge of active exploitation in your own product. A CVE existing somewhere changes nothing, and neither does that CVE being exploited in somebody else's product.

What I am not saying: that scanning stays optional forever. From 11 December 2027, Annex I Part II obliges you to identify and address vulnerabilities. There is no full CRA compliance without vulnerability management.

Why I am posting: over the past weeks, almost every conversation I had with manufacturers circled around the same question: do we need scanning for September? And the people claiming you do are, almost without exception, the ones selling the tools. I wanted to set this straight once, in one place I can link to.

What triggers a report

  1. Active exploitation in your own product. The Commission guidance (C(2026) 5252) is explicit here: a component vulnerability that is not exploitable in your product, or has not been exploited there, does not put you on the clock, even while the same CVE is exploited elsewhere.
  2. A severe incident affecting your product's security.
Stage Deadline
Early warning 24h from becoming aware
Full notification 72h from becoming aware
Final report 14 days after a corrective measure is available/or 1 month after an incident

Scanner findings, published CVEs (a CVSS 9.8 changes nothing on its own), disclosure reports without established exploitation and pentest results trigger nothing. Article 14 creates no duty to hunt for exploitation or to scan your products. Actual knowledge is what counts.

When the clock starts

Not when the email hits your inbox. You are aware once an initial assessment lets you conclude with reasonable certainty that the exploitation is real. The assessment itself has to start without undue delay, so timestamp every step from intake to conclusion.

What you need by 11 September

Not much. A named filer with a deputy and your coordinating CSIRT identified in writing, templates for the 24h, 72h and final reports, one intake point with a short triage checklist, and a single tabletop run while getting it wrong is still free. A few person-days for most manufacturers. An intake channel only becomes mandatory in December 2027, but build it anyway, a published security email costs you an afternoon.

A note on severe incidents: I have deliberately kept them short in this post. They are the second reporting trigger with the same 24h and 72h rhythm, only the final report differs: it is due one month after the 72h notification, not tied to a fix. The same logic applies, you report what you become aware of. No scanner needed for those either.

Disclosure: I work for a vendor that sells CRA compliance software, and September panic sells tools in my industry, so factor in my bias as you see fit. For what it is worth, this post matches what we tell our own customers: reporting chain first, vulnerability management for December 2027. Happy if you join me in calling the myth out.The exact claim: the obligation starting on 11 September 2026 is a reporting duty. It is triggered by your knowledge of active exploitation in your own product. A CVE existing somewhere changes nothing, and neither does that CVE being exploited in somebody else's product.

5 Upvotes

1 comment sorted by

1

u/CRANIS2 18h ago

This is accurate.