Early warning
Record the product, occurrence and information that triggered the reporting assessment.
Cyber Resilience Act reporting
Veedor connects the information available at each reporting stage to product impact, supplier evidence, mitigations and named approvals.
Test a CRA caseReporting scope
From 11 September 2026, the CRA requires manufacturers to report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements through ENISA’s Single Reporting Platform.
Official sequence
Record the product, occurrence and information that triggered the reporting assessment.
Record the information available, initial product impact, exploitation or incident context, mitigations and remaining evidence gaps.
For an actively exploited vulnerability, no later than 14 days after a corrective or mitigating measure is available; for a severe incident, within one month of the 72-hour notification.
Veedor’s role
Map supplier and internal claims to the components, products and versions in scope.
Preserve sources, available information, mitigations, unanswered questions and reporting-stage approvals.
Connect corrective measures and validation evidence to the final human-approved dossier.
Veedor does not make the legal reporting determination, provide legal advice or submit through the Single Reporting Platform on your behalf.