This page is a concise route finder for product security across the lifecycle. Detailed obligations, checklists and legal sources are maintained on dedicated topic pages so the same rules are not repeated in several places.
Choose what you need to do
Prepare a product before market placement
- Cybersecurity risk assessment and technical documentation — prepare a traceable risk assessment, SBOM and technical file for the specific model and version.
- Essential cybersecurity requirements — map Annex I to product properties and vulnerability-handling processes.
Plan support and security updates
Support periods and security updates explains how to determine and disclose end of support, provide security updates and keep them available.
Meet duties after market placement
Manufacturer duties after market placement covers conformity monitoring, vulnerabilities, corrective action, user notification and records.
Assess or submit a CRA report
- Do I need to submit a CRA report? — distinguish an actively exploited vulnerability, severe incident and another type of event.
- Reporting deadlines and information — prepare the 24-hour early warning, 72-hour notification and final report.
- Submit a CRA report — use the current mandatory channel and process.
Have you found a vulnerability or do you have another concern?
A manufacturer’s mandatory Article 14 CRA report, voluntary vulnerability disclosure, an organisation’s NIS2 incident report and a concern about possible product non-compliance are different processes. Choose the correct route for another report or concern. That page also provides the national CVD route and the NBÚ responsible-vulnerability-disclosure policy.
Law and guidance
Law: binding duties come from Regulation (EU) 2024/2847, particularly Articles 13 to 16 and Annex I. Guidance: practical material from NBÚ, the European Commission and ENISA helps organisations apply the rules but does not replace the Regulation or a product-specific assessment.