If an actively exploited vulnerability is contained in a third-party component, are all manufacturers integrating that component required to notify it?

Please refer to the European Commission’s FAQ, in particular Section 5.4 on the reporting obligations for actively exploited vulnerability contained in a third-party component, as well C(2026) 5252 - Annex - Commission guidance on the application of the Cyber Resilience Act (CRA) paragraph 218.

© 2026 European Union Agency for Cybersecurity (ENISA) • ENISA legal notice • "All you need to know about the CRA SRP" •
Disclaimer

Disclaimer: This FAQ is subject to the legal notice published on ENISA's website. Its content was extracted from ENISA's web page when this website was built; please check the original page for accuracy.