Shape

PSIRT: organising product vulnerability handling for the CRA

CRA ComplianceBy AzertyUI Team

Since 11 September 2026, the Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities and severe incidents: early warning within 24 hours, notification within 72 hours, to the designated authorities. These deadlines are only workable with a prepared organisation: a product security incident response team, or PSIRT.

A PSIRT, even at small scale

No need for a large team: what matters is clear roles and a known process. For an SME, two or three trained people and a written procedure are often enough to start.

The essential building blocks

  • A public point of contact to receive reports, for instance via a security.txt file on your website.
  • A coordinated disclosure policy: how you handle a report, how fast, how you credit researchers.
  • Triage: which products and versions are affected (thanks to the SBOM), how severe, is it being exploited?
  • Fix and distribution: patch, secure update, security advisory to customers.
  • Regulatory reporting: who decides, who sends, with what information, within the CRA deadlines.

Test before you need it

A tabletop exercise (simulating an exploited vulnerability on a Friday evening) quickly reveals the gaps: missing contacts, incomplete SBOM, blocked approvals. Better to find them in advance.

Setting up this process is part of our CRA compliance support.

Information current as of 29 September 2026. Regulations and timelines change: this article is not legal advice.

Related Tags

  • Coordinated disclosure
  • CRA
  • Divulgation coordonnée
  • Gestion des vulnérabilités
  • PSIRT
  • Reporting
  • Signalement
  • Vulnerability management

Share This Article

Shape