Cyber Resilience Act Reporting: What to Ask Your Software Vendors
The Cyber Resilience Act reporting rules put new duties on manufacturers. Not on the small companies that buy their products. But they do hand you, the buyer, a solid excuse to ask every vendor one thing: how will news of a flaw and its fix actually reach us? What follows is the customer’s side of the story in plain language - a practical list of questions and habits, not legal advice.
Table of Contents
What changed in September under the Cyber Resilience Act?
Since 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents affecting their products with digital elements. An actively exploited vulnerability? Simply a flaw that attackers are already using. According to the Commission’s Cyber Resilience Act overview, the law entered into force on 10 December 2024 and its main obligations apply from 11 December 2027.
As the Commission’s CRA reporting page explains, a manufacturer has to submit an early warning within 24 hours of becoming aware of the problem and a full notification within 72 hours.
Do the CRA reporting obligations apply to a small business buyer?
No. The duties sit with manufacturers, not with a small company that buys software, routers or other connected devices. Those reports go to authorities, and nothing here promises that a customer automatically gets a copy. Is a particular tool or online service in scope? Don’t guess. Check with each supplier.
The takeaway for small business buyers is simpler. Vendors now have to track exploited flaws against a short deadline, so it is fair to ask how the same information gets to the people who use the product.
Software vendor security questions worth sending this month
Send a short written list to each supplier of software and devices, and you will know how quickly you would hear about a problem. Keep it brief enough for a support team to answer in one reply:
- In your view, does this product fall under the Cyber Resilience Act?
- How do you tell customers about actively exploited vulnerabilities?
- Through which channel do those notices arrive, and to which address on our side?
- How are security updates from vendors like you delivered - automatically, or do we install them by hand?
- Until when will this product receive updates?
- Who do we contact when a notice is unclear?
Store the replies in writing, next to the contract or vendor record. A vague answer is information too. So is no answer at all.
Keep one list of software, devices and vendor contacts
Nobody can act on a vendor notice if nobody knows the product is in use. So start with an inventory. For each item, write down the product, the vendor, its security contact, the person in your company who owns it and how updates get installed. A spreadsheet is fine, as long as someone keeps it current.
In my experience it’s the forgotten stuff that bites: routers, printers, cameras, browser and website plug-ins. Go through the list during an annual cleanup of tools and it won’t go stale. Vendor contacts and contracts with expiry reminders can also live in a CRM such as EpicCRM, so the supplier record and the renewal date sit in the same place.
Who receives vendor notices and how fast do you install updates?
Every notice needs a named recipient, a backup person and an agreed time to act. Skip that and the warning lands in the inbox of someone on holiday. And waits. A simple routine covers it:
- Route notices to a shared mailbox instead of one person’s inbox.
- Name an owner and a deputy for each product.
- Decide how quickly updates get installed on critical tools.
- Define what happens when a fix is not yet available, such as limiting access or switching a feature off.
- Record what was done and when.
Staff who spot a warning also need a clear escalation path, so the call to patch or pause a tool reaches someone with the authority to make it.
Backups you have actually tested
A backup only counts once you have restored from it. An exploited flaw can cost you data before a patch arrives. Ask each vendor what is backed up, how often and how a restore is requested. Where the tool allows it, keep your own export of key data.
For customer records, testing CRM backup restores on a schedule shows whether the copy is usable and how long recovery takes. EpicCRM runs on EU servers with encryption, automatic backups, roles and permissions and data export, so you get both a provider-side copy and your own.
The Cyber Resilience Act puts reporting on manufacturers. The buyer’s job is smaller and fully within reach: an inventory, a named recipient for notices, a habit of installing updates fast and backups that have been proven to work.
FAQ
Does my small company have to report anything under the Cyber Resilience Act?
The reporting duties described here are placed on manufacturers, not on a company that only buys and uses products. If you also build or resell something with digital elements, check your specific case with the vendor or an adviser.
Will vendors tell customers about actively exploited vulnerabilities?
The reporting rules cover notifications to authorities. How and when customers hear about a flaw is up to the vendor, so ask which channel is used and which of your addresses receives the notice.
How do I know whether a product is covered by the CRA?
The law covers products with digital elements, but scope for a given tool or online service is for the vendor to confirm. Ask in writing and keep the answer with the contract.



