• For whom
    • Small and medium businesses
    • Sales teams
    • Marketing departments
    • Customer service departments
    • For startups
  • Features & Benefits
    • Summary
    • Contact management
    • Process Automation
    • Analytics and Reporting
    • Project management
    • Data security
  • Pricing
  • News
  • Contact
  • English
    • Polski

Try it yourself

Edit Content

Log in to our demo account
and test the capabilities of Epic CRM.

Login - [email protected]
Password - demo

Close

Log in or sign up

Edit Content

Please login to your account

Forgot Password?

Sign In
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Close
Security & Data

Cyber Resilience Act Reporting: What to Ask Your Software Vendors

September 25, 2026 Krzysztof Balicki Comments Off on Cyber Resilience Act Reporting: What to Ask Your Software Vendors
Cyber Resilience Act Reporting: What to Ask Your Software Vendors

The Cyber Resilience Act reporting rules put new duties on manufacturers. Not on the small companies that buy their products. But they do hand you, the buyer, a solid excuse to ask every vendor one thing: how will news of a flaw and its fix actually reach us? What follows is the customer’s side of the story in plain language - a practical list of questions and habits, not legal advice.

Table of Contents

  • What changed in September under the Cyber Resilience Act?
  • Do the CRA reporting obligations apply to a small business buyer?
  • Software vendor security questions worth sending this month
  • Keep one list of software, devices and vendor contacts
  • Who receives vendor notices and how fast do you install updates?
  • Backups you have actually tested
  • FAQ
    • Does my small company have to report anything under the Cyber Resilience Act?
    • Will vendors tell customers about actively exploited vulnerabilities?
    • How do I know whether a product is covered by the CRA?

What changed in September under the Cyber Resilience Act?

Since 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents affecting their products with digital elements. An actively exploited vulnerability? Simply a flaw that attackers are already using. According to the Commission’s Cyber Resilience Act overview, the law entered into force on 10 December 2024 and its main obligations apply from 11 December 2027.

As the Commission’s CRA reporting page explains, a manufacturer has to submit an early warning within 24 hours of becoming aware of the problem and a full notification within 72 hours.

Do the CRA reporting obligations apply to a small business buyer?

No. The duties sit with manufacturers, not with a small company that buys software, routers or other connected devices. Those reports go to authorities, and nothing here promises that a customer automatically gets a copy. Is a particular tool or online service in scope? Don’t guess. Check with each supplier.

The takeaway for small business buyers is simpler. Vendors now have to track exploited flaws against a short deadline, so it is fair to ask how the same information gets to the people who use the product.

Software vendor security questions worth sending this month

Send a short written list to each supplier of software and devices, and you will know how quickly you would hear about a problem. Keep it brief enough for a support team to answer in one reply:

  • In your view, does this product fall under the Cyber Resilience Act?
  • How do you tell customers about actively exploited vulnerabilities?
  • Through which channel do those notices arrive, and to which address on our side?
  • How are security updates from vendors like you delivered - automatically, or do we install them by hand?
  • Until when will this product receive updates?
  • Who do we contact when a notice is unclear?

Store the replies in writing, next to the contract or vendor record. A vague answer is information too. So is no answer at all.

Keep one list of software, devices and vendor contacts

Nobody can act on a vendor notice if nobody knows the product is in use. So start with an inventory. For each item, write down the product, the vendor, its security contact, the person in your company who owns it and how updates get installed. A spreadsheet is fine, as long as someone keeps it current.

In my experience it’s the forgotten stuff that bites: routers, printers, cameras, browser and website plug-ins. Go through the list during an annual cleanup of tools and it won’t go stale. Vendor contacts and contracts with expiry reminders can also live in a CRM such as EpicCRM, so the supplier record and the renewal date sit in the same place.

Who receives vendor notices and how fast do you install updates?

Every notice needs a named recipient, a backup person and an agreed time to act. Skip that and the warning lands in the inbox of someone on holiday. And waits. A simple routine covers it:

  1. Route notices to a shared mailbox instead of one person’s inbox.
  2. Name an owner and a deputy for each product.
  3. Decide how quickly updates get installed on critical tools.
  4. Define what happens when a fix is not yet available, such as limiting access or switching a feature off.
  5. Record what was done and when.

Staff who spot a warning also need a clear escalation path, so the call to patch or pause a tool reaches someone with the authority to make it.

Backups you have actually tested

A backup only counts once you have restored from it. An exploited flaw can cost you data before a patch arrives. Ask each vendor what is backed up, how often and how a restore is requested. Where the tool allows it, keep your own export of key data.

For customer records, testing CRM backup restores on a schedule shows whether the copy is usable and how long recovery takes. EpicCRM runs on EU servers with encryption, automatic backups, roles and permissions and data export, so you get both a provider-side copy and your own.

The Cyber Resilience Act puts reporting on manufacturers. The buyer’s job is smaller and fully within reach: an inventory, a named recipient for notices, a habit of installing updates fast and backups that have been proven to work.

FAQ

Does my small company have to report anything under the Cyber Resilience Act?

The reporting duties described here are placed on manufacturers, not on a company that only buys and uses products. If you also build or resell something with digital elements, check your specific case with the vendor or an adviser.

Will vendors tell customers about actively exploited vulnerabilities?

The reporting rules cover notifications to authorities. How and when customers hear about a flaw is up to the vendor, so ask which channel is used and which of your addresses receives the notice.

How do I know whether a product is covered by the CRA?

The law covers products with digital elements, but scope for a given tool or online service is for the vendor to confirm. Ask in writing and keep the answer with the contract.

Post navigation

Previous
Next

Search

Categories

  • Automation & Integrations (33)
  • CRM best practices and tips (56)
  • CRM Guides (41)
  • Customer Support (17)
  • Industry insights and trends (12)
  • Sales Management (45)
  • Security & Data (17)

Recent posts

  • Sales Playbook for Small Teams: What to Write Down First
    Sales Playbook for Small Teams: What to Write Down First
  • Key Account Management for Small B2B Teams: Where to Start
    Key Account Management for Small B2B Teams: Where to Start
  • Cyber Resilience Act Reporting: What to Ask Your Software Vendors
    Cyber Resilience Act Reporting: What to Ask Your Software Vendors

Tags

AI analytics automation B2B business business growth Business Software business tools checklist compliance CRM CRM Trends customer data Customer Engagement Customer Retention customer service customer support Data Management data migration data quality Data Security email marketing follow-up forecasting GDPR guide help desk KPI lead generation lead management lead scoring marketing pipeline productivity revenue Sales Sales Forecasting sales management sales pipeline sales process sales team small business software spreadsheets workflow

Related posts

Key Account Management for Small B2B Teams: Where to Start
Sales Management

Key Account Management for Small B2B Teams: Where to Start

September 26, 2026 Krzysztof Balicki Comments Off on Key Account Management for Small B2B Teams: Where to Start

Key account management means picking the few clients your business really depends on and giving each one a named owner, a written plan and a regular review. That way they stop sitting in the same queue as everyone else. And plenty of small B2B firms have exactly this problem: a handful of clients bring in […]

Overdue Invoice Follow-Up: Getting Paid and Keeping the Client
CRM best practices and tips

Overdue Invoice Follow-Up: Getting Paid and Keeping the Client

September 5, 2026 Krzysztof Balicki Comments Off on Overdue Invoice Follow-Up: Getting Paid and Keeping the Client

A polite, scheduled overdue invoice follow-up gets you paid faster than ad hoc chasing. It also protects the relationship, because the client knows what to expect at every step. Most small B2B firms are fine at sending invoices on time. Chasing them? Different story. It runs on mood and memory, and the fear of sounding […]

Win-Loss Analysis for Small Sales Teams: Learning From Lost Deals
Sales Management

Win-Loss Analysis for Small Sales Teams: Learning From Lost Deals

July 29, 2026 Krzysztof Balicki Comments Off on Win-Loss Analysis for Small Sales Teams: Learning From Lost Deals

Win-loss analysis boils down to three things: write down why every deal closed, go through those reasons together on a fixed schedule, and change one thing in how your team sells. Is your pipeline full of deals marked lost with zero explanation? Do the same mistakes come back every quarter? Then this is the fix. […]

Do you want to receive news and updates?


    Epic CRM

    CRM for small and medium businesses: sales, tasks, contracts and customer service in one place.

    Resources
    • Features
    • Pricing
    • News
    • FAQ
    • Terms of Service
    • Privacy Policy
    • Cookie Policy
    • DPA
    • Cookie settings
    • Features
    • Pricing
    • News
    • FAQ
    • Terms of Service
    • Privacy Policy
    • Cookie Policy
    • DPA
    • Cookie settings
    Partners
    • Botino: AI voicebots
    • Web Systems Łódź
    • Sellaro: eCommerce integrations
    • MailCraft: email marketing
    • Inteleo: AI assistants
    • Botino: AI voicebots
    • Web Systems Łódź
    • Sellaro: eCommerce integrations
    • MailCraft: email marketing
    • Inteleo: AI assistants

    All rights reserved 2024 - 2026 ©EpicCRM

    • Developed by Web Systems