CRA Compliance

ENISA on the Future of EU Vulnerability Disclosure: Key Insights for Manufacturers

By CVD Portal
8 min read

In an interview with Help Net Security, Nuno Rodrigues Carvalho, Head of Sector for Incident and Vulnerability Services at ENISA, addressed three key topics for EU manufacturers: CVE resilience, Cyber Resilience Act accountability, and the commercial value of coordinated disclosure.

This post maps his statements to the practical steps manufacturers must take before the September 2026 enforcement deadline.

Building Resilience in Vulnerability Identification

Global vulnerability tracking has historically depended on a single US-funded operational backbone. ENISA is developing the European Vulnerability Database (EUVD) as an interoperable, complementary layer that strengthens global resilience.

For manufacturers, enrichment data for vulnerabilities comes from multiple authoritative sources:

  • CVE identifiers provide universal naming consistency.
  • Vendor advisories supply technical mitigation instructions.
  • National CSIRTs and ENISA provide regional and sector-specific operational context.

CVD Portal integrates all three data streams, offering EUVD intelligence, NVD enrichment, and automated national CSIRT escalation routing.

CRA Enforcement Realities

Carvalho outlined the specific statutory reporting obligations under Article 14:

  • 24-hour early warning to the Single Reporting Platform upon awareness of active exploitation.
  • 72-hour detailed notification covering technical scope and severity.
  • Final report within 14 days of a fix (for vulnerabilities) or within one month (for severe incidents).

The Single Reporting Platform, operated by ENISA, serves as the central reporting gateway for all Member States. These reporting rules apply to all supported products currently on the EU market from 11 September 2026.

Manufacturers without functioning vulnerability management processes face market surveillance penalties and potential product sales bans.

NIS2 vs. CRA Obligations

Carvalho clarified a common point of industry confusion:

  • NIS2 obliges national CSIRTs to establish coordinated vulnerability disclosure handling capabilities. It establishes organizational risk governance for operators of essential services.
  • The CRA places direct legal duties on product manufacturers to maintain vulnerability channels and submit mandatory incident notifications.

For hardware and software manufacturers, the CRA is the primary regulatory standard.

Vulnerability Handling as a Commercial Advantage

Carvalho highlighted that responsive vulnerability management is now a competitive differentiator in enterprise procurement.

Buyers in regulated sectors actively evaluate how suppliers handle vulnerability reports. A working intake portal, rapid acknowledgment SLAs, and machine-readable CSAF advisories provide verifiable proof of product maturity.

Summary

Vulnerability infrastructure in Europe is moving toward strict regulatory accountability and machine-readable transparency.

Setting up verified intake channels, triage workflows, and Single Reporting Platform access ensures readiness before September 2026. CVD Portal provides this complete compliance infrastructure out of the box.

Stay compliant with the Cyber Resilience Act

Check your readiness with the CRA Readiness Checklist, or compare plans on pricing.

Get Started for Free

CRA deadline briefing

A short email on the Cyber Resilience Act reporting obligations and the run-up to 11 September 2026.

We use your email only to send the briefing. Unsubscribe any time with one click.