Skip to main content
Press release

Vibgrate Evidence links vulnerable components to released products for CRA reporting

Signed, reproducible records show which released product versions contain components affected by an actively exploited vulnerability, helping manufacturers establish scope and prepare CRA Article 14 notifications.

From September 11, 2026, Article 14 of the EU Cyber Resilience Act (CRA) requires manufacturers to report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements.

An early warning must be submitted without undue delay and within 24 hours of the manufacturer becoming aware of the vulnerability or incident. A more detailed notification follows within 72 hours. For an actively exploited vulnerability, a final report is required no later than 14 days after a corrective or mitigating measure becomes available.

Notifications are submitted through the CRA Single Reporting Platform. These reporting requirements apply to products with digital elements made available on the EU market, including products placed on the market before most other CRA obligations become applicable on December 11, 2027.

Under that deadline, the practical challenge is establishing exposure. Which released products contain the affected component? Which versions are involved? Where were those versions made available, and are they still supported?

Many teams have to reconstruct those answers from build systems, release records, spreadsheets, and institutional memory. That is slow during the first hours of an incident and difficult to defend when the decision is examined later.

Vibgrate Evidence builds the answer from release records captured before an incident occurs. Manufacturers register their products with digital elements, preserve a component manifest for each release, and record relevant market and support information.

When a vulnerability is identified, Vibgrate compares it with the preserved manifests and produces a signed evidence package showing which product versions match and which do not. The package preserves the inputs and results so that the conclusion can be reproduced and verified offline.

This replaces an investigation assembled under deadline with evidence generated from records that already exist.

Vibgrate Evidence supports technical investigation and reporting preparation. It does not determine whether an organization is legally required to notify, make compliance decisions, or provide certification. It is not a substitute for legal advice.

The same versioned product and component records can support additional reporting regimes as requirements evolve.

Vibgrate Evidence is available now through the Vibgrate CLI and Vibgrate Cloud under Govern ▸ Evidence.

“An SBOM tells you what was recorded in a build. Under a reporting deadline, manufacturers need to connect that record to a released product version, its release history, and the evidence supporting the exposure decision.”
Peter Chapman — Founder, Vibgrate

Facts and primary sources

  • CRA Article 14 reporting begins on September 11, 2026. An early warning is due within 24 hours of becoming aware of an actively exploited vulnerability or qualifying severe incident. A more detailed notification follows within 72 hours. Read the European Commission's reporting guidance
  • The European Commission published non-binding implementation guidance on July 27, 2026, covering reporting obligations, risk assessment, product scope, substantial modification, and support periods. Read the Commission guidance
  • Most CRA provisions apply from December 11, 2027. Article 14 reporting begins earlier and applies to products with digital elements already made available on the EU market. Read the European Commission's CRA summary

About Vibgrate

Vibgrate is a software intelligence platform that helps teams find aging dependencies, assess security exposure, and plan modernization. Its free CLI maps codebases and produces DriftScore, a transparent measure of dependency, framework, and runtime drift. Vibgrate Cloud adds portfolio visibility, governance workflows, and verifiable evidence for security and regulatory decisions. Vibgrate Evidence preserves version-specific component and release records so teams can reproduce historical exposure findings. Vibgrate AI Context gives coding agents version-matched documentation and precise repository context while reducing unnecessary token use. Vibgrate publishes its scoring methodology openly, allowing researchers to inspect the evidence, assumptions, and formulas behind its results.

25-word boilerplate

Vibgrate helps software teams find aging dependencies, assess security exposure, and plan modernization using verifiable evidence produced by its free code-scanning CLI and cloud platform.

50-word boilerplate

Vibgrate is a code drift intelligence platform for software teams. Its free CLI maps a codebase and identifies drift across dependencies, frameworks, and runtimes. Vibgrate Cloud turns the same scan data into portfolio visibility, governance workflows, security prioritization, and verifiable evidence for modernization decisions, regulatory reporting, and ongoing software assurance.

Press inquiries

Peter Chapman, Founder · press@vibgrate.com