Vulnerability Management
The EU Cyber Resilience Act (CRA) obliges manufacturers to maintain and provide comprehensive, machine-readable documentation covering all aspects of their cybersecurity lifecycle.
This includes detailed vulnerability management records (identification, triage, remediation, and coordinated disclosure), a secure and traceable software-update process (with digital signatures, rollback protection, and verifiable release metadata), and complete compliance evidence demonstrating conformity with CRA Annex I Part II and Article 14 reporting obligations.
In practice, this means that every product must expose a structured, version-controlled data set — such as a JSON or SPDX-based document — that describes its SBOM/HBOM, vulnerability handling workflow, update channels, applied patches, incident reports, and responsible roles within the organization, ensuring full transparency for both market surveillance authorities and downstream integrators.