Kilde › Guides › CRA › CRA vulnerability handling: the Annex …

CRA vulnerability handling: the Annex I Part II duties, mapped

Current to 26 August 2026 · updates land in the changelog.

Alongside reporting sits the standing discipline: the vulnerability-handling requirements of Annex I Part II — the process obligations that make the reporting duty survivable in practice.

The duties, mapped

Where teams stumble

Three patterns recur. First, SBOMs generated once at release and never refreshed — the duty is to maintain identification of components, not to produce an artefact for the file. Second, CVD policies copied from templates but not enforced — the annex requires both. Third, treating the public-disclosure duty as optional PR: once the fix ships, disclosure of the fixed vulnerability is a listed requirement, not a courtesy.

How this connects to the clocks

The handling duties are continuous; the Article 14 clocks fire on the defined triggers. A functioning handling process is what lets you meet a 24-hour early warning without heroics — the intake channel, the component map and the update pipeline are the same machinery, exercised calmly.

Related guides

Quick answers

Does the CRA require an SBOM?
Yes — identification of vulnerabilities and components including a software bill of materials in a commonly used machine-readable format, covering at least the product's top-level dependencies. It is not required to be public, and no specific format has been mandated at our verification date.
Are security patches required to be free under the CRA?
Security updates are to be disseminated without delay and free of charge, with a narrow carve-out for tailor-made products where otherwise agreed with a business user.
Is a CVD policy mandatory?
Yes — manufacturers must put in place and enforce a coordinated vulnerability disclosure policy; its contents are not prescribed by the CRA.
Be reporting-ready before 11 September 2026.

The CRA Reporting-Ready Pack: the staged 24h / 72h / final-report runbook and templates, vulnerability-vs-incident triage worksheet, CSIRT-routing and main-establishment worksheet, platform registration runbook, CVD policy and evidence log — built from the regulation and the ENISA platform guides, with pinpoint citations.

Get the pack — US$390 Free 4-page sample (PDF)

Instant download · 14-day unconditional refund · single-organisation licence · full product page

General information only — not legal advice, and never a conformity assessment. Whether a specific product falls in a listed category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, and reporting-platform mechanics are ENISA-published material marked subject to change. Sources are Regulation (EU) 2024/2847 (CELEX 32024R2847; Annex III/IV item texts read verbatim from EUR-Lex) and our audited kit research. © 2026 Kilde.

Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com