Cyber Resilience Act (CRA)
Table of Contents
Chapter I – GENERAL PROVISIONS
Chapter II – OBLIGATIONS OF ECONOMIC OPERATORS AND PROVISIONS IN RELATION TO FREE AND OPEN-SOURCE SOFTWARE
Chapter III – CONFORMITY OF THE PRODUCT WITH DIGITAL ELEMENTS
Chapter IV – NOTIFICATION OF CONFORMITY ASSESSMENT BODIES
Chapter V – MARKET SURVEILLANCE AND ENFORCEMENT
Chapter VI – DELEGATED POWERS AND COMMITTEE PROCEDURE
Chapter VII – CONFIDENTIALITY AND PENALTIES
Chapter VIII – TRANSITIONAL AND FINAL PROVISIONS
Recitals (130)
Annexes
Recital 71
(71) When manufacturers notify an actively exploited vulnerability or a severe incident having an impact on the security of the product with digital elements, they should indicate how sensitive they consider the notified information to be. The CSIRT designated as coordinator initially receiving the notification should take this information into account when assessing whether the notification gives rise to exceptional circumstances that justify a delay in the dissemination of the notification to the other relevant CSIRTs designated as coordinators based on justified cybersecurity-related grounds. It should also take that information into account when assessing whether the notification of an actively exploited vulnerability gives rise to particularly exceptional circumstances that justify that the full notification is not made available simultaneously to ENISA. Finally, CSIRTs designated as coordinators should be able to take that information into account when determining appropriate measures to mitigate the risks stemming from such vulnerabilities and incidents.