Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority

Do I need to submit a CRA report?

Last updated:

Step 1: Identify your role

Step 2: Identify the occurrence

An actively exploited vulnerability has reliable evidence that a malicious actor exploited it in a system without the owner’s permission. Internal discovery, a published CVE or theoretical exploitability alone is insufficient.

A severe incident negatively affects or could affect the product’s ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions; or has led or could lead to malicious code being introduced or executed in the product or a user’s systems.

The absence of a fix does not stop the clock. If the threshold is uncertain, escalate internally immediately and record the evidence; a help contact does not replace mandatory submission.

From 11 September 2026 the duty also covers products made available on the Union market before the CRA generally applies. Legal basis: CRA Article 14.