Industry News

VDMA Releases CRA Vulnerability Handling Guideline for Industrial Manufacturers

The German Engineering Federation (VDMA) published its official CRA Vulnerability Handling Guideline in April 2026. The VDMA Industrial Security Working Group created the document with representatives from Siemens, ifm, Rolls-Royce Power Systems, Liebherr, GEA Group, and Weidmüller. The publication provides practical implementation rules for Regulation (EU) 2024/2847 (Cyber Resilience Act).

The guideline addresses machinery builders, component manufacturers, and industrial automation providers. It defines organizational, procedural, and technical controls across the product lifecycle.

Implementation of Harmonised Standard prEN 40000-1-3

The guideline aligns operational engineering with emerging European standards under the CRA:

  • prEN 40000-1-3: Vulnerability handling requirements for products with digital elements.
  • ISO/IEC 29147 and ISO/IEC 30111: Vulnerability disclosure and internal handling workflows.
  • BSI TR-03183-3: Requirements for manufacturers of IoT and industrial digital products.
  • FIRST PSIRT Framework: Operational team structure and incident response roles.

Critical Deadlines for Machinery Manufacturers

The VDMA publication emphasizes essential operational timelines:

  1. 7-Day Intake Response: Manufacturers must acknowledge incoming vulnerability reports to finders within 7 calendar days.
  2. 24-Hour Early Warning: Under CRA Article 14(1), manufacturers must submit an early warning to the ENISA Single Reporting Platform (SRP) within 24 hours of confirming active exploitation.
  3. 72-Hour Detailed Notification: A comprehensive report with root cause analysis and initial mitigations must follow within 72 hours.
  4. 14-Day Final Report: A final report must reach ENISA within 14 days after a security mitigation or patch becomes available.

Core Compliance Artifacts

Every machinery manufacturer in scope must maintain four core items:

  • An internal vulnerability handling policy for engineering escalation.
  • A public Coordinated Vulnerability Disclosure (CVD) policy.
  • A machine-readable security.txt file (RFC 9116) at /.well-known/security.txt.
  • Structured security advisories (CSAF 2.0) for released patches.

Mandatory Article 14 reporting obligations apply starting 11 September 2026.


Porta Regulus B.V. provides CRA compliance infrastructure. Deploy a managed RFC 9116 vulnerability disclosure portal and automate Article 14 reporting workflows at cvdportal.com.

Prepare your CRA vulnerability intake and reporting workflows before 11 September 2026.

Get started free