Do you need VEX documents for CRA compliance?
The Cyber Resilience Act never uses the word VEX. It still makes exploitability the legal test, and it still requires you to share vulnerability information about third-party components. ENISA surveyed 334 organisations and found 76 percent rate supplier exploitability claims as critical or important. Here are the four statuses, the five justifications, the three competing formats, and how to choose one.