Back to use cases

Cyber Resilience Act reporting

Prepare the reporting record without losing the closure case.

Veedor connects the information available at each reporting stage to product impact, supplier evidence, mitigations and named approvals.

Test a CRA case

Reporting scope

Not every CVE starts the clock.

From 11 September 2026, the CRA requires manufacturers to report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements through ENISA’s Single Reporting Platform.

Official sequence

Keep the available facts, gaps and decisions visible at every stage.

Within 24 hours01

Early warning

Record the product, occurrence and information that triggered the reporting assessment.

Within 72 hours02

Full notification

Record the information available, initial product impact, exploitation or incident context, mitigations and remaining evidence gaps.

Final report03

Complete the record

For an actively exploited vulnerability, no later than 14 days after a corrective or mitigating measure is available; for a severe incident, within one month of the 72-hour notification.

Veedor’s role

Evidence preparation remains connected to operational closure.

01

Product impact

Map supplier and internal claims to the components, products and versions in scope.

02

Reporting evidence

Preserve sources, available information, mitigations, unanswered questions and reporting-stage approvals.

03

Final closure

Connect corrective measures and validation evidence to the final human-approved dossier.

Veedor prepares. Your organisation submits.

Veedor does not make the legal reporting determination, provide legal advice or submit through the Single Reporting Platform on your behalf.

Cyber Resilience Act reporting | Veedor