Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority

Vulnerabilities: What manufacturer must do after placing the product in the market

Published: Last updated:

The product is on the market. Security work does not end there – on the contrary, the next phase begins.

Annex I, Part 2 of the CRA states clearly: the manufacturer must actively manage vulnerabilities throughout the entire period the product is in service. This is one of the most important changes introduced by the CRA.

Documented vulnerability management process: The manufacturer must have a formal, written procedure for identifying, assessing, reporting and addressing vulnerabilities. Internal ‘we knew about it’ is not enough.

Free and timely security updates: Vulnerability fixes must be made available to users free of charge. The manufacturer shall specify a support period – and must adhere to it.

Reporting of actively exploited vulnerabilities: From 11 September 2026 – if a manufacturer discovers an actively exploited vulnerability, it must report it to the National Cybersecurity Center (NBÚ) within 24 hours. This must be followed by a detailed report within 72 hours.

SBOM – Software Bill of Materials: The manufacturer must know what their software consists of – including open-source libraries. Without this, they cannot respond quickly to a new vulnerability.

Coordinated Vulnerability Disclosure (CVD): The manufacturer must have a policy and a channel through which security researchers (or anyone) can report a discovered vulnerability, known as ‘responsible disclosure’.

What is an SBOM and why does it matter?

Think of it as the ingredients list on a food packet – but for software. An SBOM is a machine-readable list of all the components, libraries and dependencies that make up a product. When a critical vulnerability emerges in an open-source component (e.g. the now-famous Log4j), a vendor with an SBOM can immediately determine whether they are affected – and take action.