From September 11, 2026, Article 14 of the EU Cyber Resilience Act (CRA) requires manufacturers to report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements.
An early warning must be submitted without undue delay and within 24 hours of the manufacturer becoming aware of the vulnerability or incident. A more detailed notification follows within 72 hours. For an actively exploited vulnerability, a final report is required no later than 14 days after a corrective or mitigating measure becomes available.
Notifications are submitted through the CRA Single Reporting Platform. These reporting requirements apply to products with digital elements made available on the EU market, including products placed on the market before most other CRA obligations become applicable on December 11, 2027.
Under that deadline, the practical challenge is establishing exposure. Which released products contain the affected component? Which versions are involved? Where were those versions made available, and are they still supported?
Many teams have to reconstruct those answers from build systems, release records, spreadsheets, and institutional memory. That is slow during the first hours of an incident and difficult to defend when the decision is examined later.
Vibgrate Evidence builds the answer from release records captured before an incident occurs. Manufacturers register their products with digital elements, preserve a component manifest for each release, and record relevant market and support information.
When a vulnerability is identified, Vibgrate compares it with the preserved manifests and produces a signed evidence package showing which product versions match and which do not. The package preserves the inputs and results so that the conclusion can be reproduced and verified offline.
This replaces an investigation assembled under deadline with evidence generated from records that already exist.
Vibgrate Evidence supports technical investigation and reporting preparation. It does not determine whether an organization is legally required to notify, make compliance decisions, or provide certification. It is not a substitute for legal advice.
The same versioned product and component records can support additional reporting regimes as requirements evolve.
Vibgrate Evidence is available now through the Vibgrate CLI and Vibgrate Cloud under Govern ▸ Evidence.