<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>ActLume blog</title><description>Practical CRA Article 14 guidance for commercial manufacturer reporting teams.</description><link>https://actlume.com/blog/</link><language>en</language><item><title>CRA Article 14: the 24h, 72h and final-report sequence</title><link>https://actlume.com/blog/cra-article-14-reporting-24-72-final-report/</link><guid isPermaLink="true">https://actlume.com/blog/cra-article-14-reporting-24-72-final-report/</guid><description>Both Article 14 tracks start with 24-hour and 72-hour stages, but their final-report clocks start from different events.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>When does the CRA Article 14 clock start?</title><link>https://actlume.com/blog/when-cra-article-14-clock-starts/</link><guid isPermaLink="true">https://actlume.com/blog/when-cra-article-14-clock-starts/</guid><description>The 24-hour and 72-hour windows run from manufacturer awareness of an actively exploited vulnerability or a severe product-security incident.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>What is an actively exploited vulnerability under the CRA?</title><link>https://actlume.com/blog/actively-exploited-vulnerability-meaning/</link><guid isPermaLink="true">https://actlume.com/blog/actively-exploited-vulnerability-meaning/</guid><description>An actively exploited vulnerability requires reliable evidence that a malicious actor exploited a vulnerability without the system owner&apos;s permission.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>How does the CRA define a severe product-security incident?</title><link>https://actlume.com/blog/severe-incident-cra-test/</link><guid isPermaLink="true">https://actlume.com/blog/severe-incident-cra-test/</guid><description>Article 14 treats an incident as severe when it meets either of two product-security impact tests concerning protected data, functions, or malicious code.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>What belongs in a CRA 24-hour early warning?</title><link>https://actlume.com/blog/cra-24-hour-early-warning/</link><guid isPermaLink="true">https://actlume.com/blog/cra-24-hour-early-warning/</guid><description>The first Article 14 stage is an early warning due without undue delay and within 24 hours of awareness, not a finished investigation report.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Building the CRA 72-hour vulnerability notification</title><link>https://actlume.com/blog/cra-72-hour-vulnerability-notification/</link><guid isPermaLink="true">https://actlume.com/blog/cra-72-hour-vulnerability-notification/</guid><description>The 72-hour vulnerability stage adds available product, exploit, vulnerability, mitigation, user-action, and sensitivity information.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Building the CRA 72-hour severe-incident notification</title><link>https://actlume.com/blog/cra-72-hour-incident-notification/</link><guid isPermaLink="true">https://actlume.com/blog/cra-72-hour-incident-notification/</guid><description>The 72-hour incident stage carries available general information, an initial assessment, and corrective or mitigating measures.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>When is the CRA vulnerability final report due?</title><link>https://actlume.com/blog/cra-vulnerability-final-report/</link><guid isPermaLink="true">https://actlume.com/blog/cra-vulnerability-final-report/</guid><description>The final report for an actively exploited vulnerability is due no later than 14 days after a corrective or mitigating measure becomes available.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>When is the CRA severe-incident final report due?</title><link>https://actlume.com/blog/cra-incident-final-report/</link><guid isPermaLink="true">https://actlume.com/blog/cra-incident-final-report/</guid><description>The final report for a severe incident is due within one month after the 72-hour incident notification.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>The CRA has two Article 14 reporting tracks</title><link>https://actlume.com/blog/cra-two-reporting-tracks/</link><guid isPermaLink="true">https://actlume.com/blog/cra-two-reporting-tracks/</guid><description>Article 14 separately covers actively exploited vulnerabilities and severe incidents affecting product security, with distinct final-report rules.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>What if CRA facts are incomplete at 24 hours?</title><link>https://actlume.com/blog/cra-24-hour-report-incomplete-facts/</link><guid isPermaLink="true">https://actlume.com/blog/cra-24-hour-report-incomplete-facts/</guid><description>The CRA early warning comes before the fuller 72-hour notification, so teams need a controlled way to report known facts and preserve uncertainty.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Keep one evidence trail across CRA reporting stages</title><link>https://actlume.com/blog/cra-reporting-evidence-trail/</link><guid isPermaLink="true">https://actlume.com/blog/cra-reporting-evidence-trail/</guid><description>CRA notifications develop across the 24-hour, 72-hour, and final stages, making a traceable record of additions and corrections essential.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>How to record the CRA awareness timestamp</title><link>https://actlume.com/blog/record-cra-awareness-timestamp/</link><guid isPermaLink="true">https://actlume.com/blog/record-cra-awareness-timestamp/</guid><description>CRA reporting windows run from manufacturer awareness, so the case record should distinguish signal receipt, assessment, and the trigger decision.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Build a CRA escalation chain that works after hours</title><link>https://actlume.com/blog/cra-after-hours-escalation/</link><guid isPermaLink="true">https://actlume.com/blog/cra-after-hours-escalation/</guid><description>CRA early warnings and notifications use hour-based deadlines from awareness, so reporting ownership needs tested backups outside normal schedules.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>How to document a CRA decision not to report</title><link>https://actlume.com/blog/document-cra-non-reportable-decision/</link><guid isPermaLink="true">https://actlume.com/blog/document-cra-non-reportable-decision/</guid><description>A non-report decision should show how the evidence was tested separately against the CRA definitions for active exploitation and severe incidents.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>How the CRA Single Reporting Platform works</title><link>https://actlume.com/blog/how-cra-single-reporting-platform-works/</link><guid isPermaLink="true">https://actlume.com/blog/how-cra-single-reporting-platform-works/</guid><description>The CRA platform gives manufacturers one electronic entry point that routes a notification to the coordinating CSIRT and ENISA.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Who does what in the CRA reporting chain?</title><link>https://actlume.com/blog/cra-reporting-chain-responsibilities/</link><guid isPermaLink="true">https://actlume.com/blog/cra-reporting-chain-responsibilities/</guid><description>Manufacturers submit; ENISA manages the platform; coordinating CSIRTs receive, assess, and ordinarily disseminate Article 14 notifications.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>How to choose the CRA coordinating CSIRT</title><link>https://actlume.com/blog/choose-cra-coordinating-csirt/</link><guid isPermaLink="true">https://actlume.com/blog/choose-cra-coordinating-csirt/</guid><description>For an EU-established manufacturer, the CRA starts with the Member State where product-cybersecurity decisions are predominantly taken.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Where a CRA report goes after submission</title><link>https://actlume.com/blog/cra-onward-dissemination/</link><guid isPermaLink="true">https://actlume.com/blog/cra-onward-dissemination/</guid><description>The coordinating CSIRT ordinarily shares a CRA notification with relevant CSIRTs where the affected product was made available.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>CRA delayed dissemination is an exceptional route</title><link>https://actlume.com/blog/cra-delayed-dissemination/</link><guid isPermaLink="true">https://actlume.com/blog/cra-delayed-dissemination/</guid><description>A coordinating CSIRT may delay onward dissemination only under the CRA&apos;s exceptional, justified cybersecurity conditions and for a strictly necessary period.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>How the CRA routes reports from non-EU manufacturers</title><link>https://actlume.com/blog/cra-non-eu-routing-cascade/</link><guid isPermaLink="true">https://actlume.com/blog/cra-non-eu-routing-cascade/</guid><description>A manufacturer with no EU main establishment follows an ordered CRA routing test based on its representative, importer, distributor, then users.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Build continuity for CRA reporting access</title><link>https://actlume.com/blog/cra-srp-access-readiness/</link><guid isPermaLink="true">https://actlume.com/blog/cra-srp-access-readiness/</guid><description>Prepare an internal primary-and-backup submission path around the CRA&apos;s staged reporting deadlines without relying on unverified platform mechanics.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>A CRA report is one submission, not two filings</title><link>https://actlume.com/blog/one-cra-submission-not-two/</link><guid isPermaLink="true">https://actlume.com/blog/one-cra-submission-not-two/</guid><description>Manufacturers submit once through the CRA platform, which routes the notification to the coordinating CSIRT and makes it available to ENISA.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>When the CRA requires an impacted-user notice</title><link>https://actlume.com/blog/cra-impacted-user-notification/</link><guid isPermaLink="true">https://actlume.com/blog/cra-impacted-user-notification/</guid><description>After awareness of an actively exploited vulnerability or severe product-security incident, the manufacturer must inform impacted users and sometimes all users.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>What a useful CRA user notice needs to say</title><link>https://actlume.com/blog/cra-user-notice-content/</link><guid isPermaLink="true">https://actlume.com/blog/cra-user-notice-content/</guid><description>A CRA user notice should identify the affected product and give deployable mitigation or corrective steps where those measures are necessary.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>When a component vulnerability becomes your CRA report</title><link>https://actlume.com/blog/cra-third-party-component-reporting/</link><guid isPermaLink="true">https://actlume.com/blog/cra-third-party-component-reporting/</guid><description>A supplier&apos;s exploited flaw does not answer the final-product question; the manufacturer must establish whether its own product contains and is affected by it.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Build the CRA handoff to a component maintainer</title><link>https://actlume.com/blog/cra-component-maintainer-handoff/</link><guid isPermaLink="true">https://actlume.com/blog/cra-component-maintainer-handoff/</guid><description>The CRA requires manufacturers that identify an integrated-component vulnerability to report it upstream and address it in their own product.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Map vulnerable components to CRA product versions</title><link>https://actlume.com/blog/map-components-to-cra-product-versions/</link><guid isPermaLink="true">https://actlume.com/blog/map-components-to-cra-product-versions/</guid><description>CRA reporting needs product-specific information, so component evidence must resolve to shipped product versions rather than stop at a dependency name.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Keep stable identifiers across a CRA reporting case</title><link>https://actlume.com/blog/cra-report-identifiers/</link><guid isPermaLink="true">https://actlume.com/blog/cra-report-identifiers/</guid><description>Use one internal case anchor to reconcile the manufacturer, product, affected versions, evidence, and staged Article 14 submissions.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Build the Member State record for a CRA warning</title><link>https://actlume.com/blog/cra-member-state-availability-record/</link><guid isPermaLink="true">https://actlume.com/blog/cra-member-state-availability-record/</guid><description>The CRA early warning identifies, where applicable, Member States where the manufacturer knows the product was made available.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Build the pre-11 September 2026 exploitation baseline</title><link>https://actlume.com/blog/cra-pre-deadline-exploitation-awareness/</link><guid isPermaLink="true">https://actlume.com/blog/cra-pre-deadline-exploitation-awareness/</guid><description>Article 14 reporting applies from 11 September 2026, so manufacturers need a dated baseline that separates earlier evidence from later awareness events.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>CRA reporting can apply to manufacturers outside the EU</title><link>https://actlume.com/blog/cra-reporting-non-eu-manufacturers/</link><guid isPermaLink="true">https://actlume.com/blog/cra-reporting-non-eu-manufacturers/</guid><description>Manufacturer location does not remove CRA reporting when an in-scope product is made available on the Union market.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>When a CRA importer or distributor becomes the manufacturer</title><link>https://actlume.com/blog/cra-importer-distributor-manufacturer-role/</link><guid isPermaLink="true">https://actlume.com/blog/cra-importer-distributor-manufacturer-role/</guid><description>An importer or distributor takes manufacturer obligations, including Articles 13 and 14, when it uses its own name or trademark or substantially modifies the product.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>The CRA reporting boundary for open-source stewards</title><link>https://actlume.com/blog/cra-open-source-steward-reporting/</link><guid isPermaLink="true">https://actlume.com/blog/cra-open-source-steward-reporting/</guid><description>Article 24 links steward vulnerability reporting to development involvement and severe-incident reporting to development systems the steward provides.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Is an open-source maintainer a CRA steward?</title><link>https://actlume.com/blog/cra-maintainer-or-open-source-steward/</link><guid isPermaLink="true">https://actlume.com/blog/cra-maintainer-or-open-source-steward/</guid><description>A CRA open-source software steward is a legal person providing systematic, sustained support for specified software intended for commercial activities.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Resolve conflicting CRA exploitation signals</title><link>https://actlume.com/blog/resolve-conflicting-cra-exploitation-signals/</link><guid isPermaLink="true">https://actlume.com/blog/resolve-conflicting-cra-exploitation-signals/</guid><description>A CRA active-exploitation decision turns on reliable evidence of malicious use without the system owner&apos;s permission, not on a label or score alone.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Separate product-security events from enterprise incidents</title><link>https://actlume.com/blog/separate-product-security-from-enterprise-incidents/</link><guid isPermaLink="true">https://actlume.com/blog/separate-product-security-from-enterprise-incidents/</guid><description>CRA severe-incident reporting concerns an incident that affects or can affect a product&apos;s ability to protect specified data or functions, or enables malicious code.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Build a manufacturer register for CRA reporting</title><link>https://actlume.com/blog/cra-reporting-manufacturer-register/</link><guid isPermaLink="true">https://actlume.com/blog/cra-reporting-manufacturer-register/</guid><description>CRA Article 14 duties attach to the manufacturer of the affected product, so a reporting runbook needs a product-specific legal-entity map.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Build a handoff packet for each CRA report stage</title><link>https://actlume.com/blog/cra-stage-handoff-packet/</link><guid isPermaLink="true">https://actlume.com/blog/cra-stage-handoff-packet/</guid><description>Preserve the approved facts, unresolved questions, and filing evidence at the early-warning, 72-hour, and final Article 14 stages.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Classify CRA report sensitivity before submission</title><link>https://actlume.com/blog/classify-cra-report-sensitivity/</link><guid isPermaLink="true">https://actlume.com/blog/classify-cra-report-sensitivity/</guid><description>CRA 72-hour notifications indicate, where applicable, how sensitive the manufacturer considers the reported information to be.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Triage one event under both the CRA and NIS2</title><link>https://actlume.com/blog/cra-and-nis2-parallel-triage/</link><guid isPermaLink="true">https://actlume.com/blog/cra-and-nis2-parallel-triage/</guid><description>The same security event can require separate assessment under the CRA&apos;s product-manufacturer test and NIS2 rules applying to an affected entity.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Triage a product incident under the CRA and GDPR</title><link>https://actlume.com/blog/cra-and-gdpr-breach-triage/</link><guid isPermaLink="true">https://actlume.com/blog/cra-and-gdpr-breach-triage/</guid><description>A security event may require both a CRA product-security assessment and a GDPR personal-data-breach assessment because the regimes ask different questions.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Decide when to use CRA voluntary reporting</title><link>https://actlume.com/blog/cra-voluntary-reporting-decision/</link><guid isPermaLink="true">https://actlume.com/blog/cra-voluntary-reporting-decision/</guid><description>CRA Article 15 permits voluntary notification of vulnerabilities, cyber threats, incidents, and near misses beyond the narrower mandatory Article 14 triggers.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Prove delivery of a CRA user notice</title><link>https://actlume.com/blog/cra-user-notice-delivery-evidence/</link><guid isPermaLink="true">https://actlume.com/blog/cra-user-notice-delivery-evidence/</guid><description>CRA user communication is risk-based: manufacturers inform impacted users and, where appropriate, all users without implying that every case requires indiscriminate public disclosure.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Separate the CRA&apos;s 2026 and 2027 workstreams</title><link>https://actlume.com/blog/cra-2026-and-2027-deadlines/</link><guid isPermaLink="true">https://actlume.com/blog/cra-2026-and-2027-deadlines/</guid><description>CRA conformity-body provisions apply from 11 June 2026, Article 14 reporting from 11 September 2026, and most remaining provisions from 11 December 2027.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Bring legacy products into CRA reporting triage</title><link>https://actlume.com/blog/cra-reporting-legacy-products/</link><guid isPermaLink="true">https://actlume.com/blog/cra-reporting-legacy-products/</guid><description>CRA Article 14 reporting applies to in-scope products made available before 11 December 2027, not only to products launched after the main application date.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Record when a CRA corrective measure becomes available</title><link>https://actlume.com/blog/cra-corrective-measure-available-timestamp/</link><guid isPermaLink="true">https://actlume.com/blog/cra-corrective-measure-available-timestamp/</guid><description>For an actively exploited vulnerability, the CRA final report is due no later than 14 days after a corrective or mitigating measure becomes available.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Do not mistake CRA small-business penalty relief for a deadline waiver</title><link>https://actlume.com/blog/cra-small-business-24-hour-rule/</link><guid isPermaLink="true">https://actlume.com/blog/cra-small-business-24-hour-rule/</guid><description>CRA Article 64 prevents fines for certain micro and small manufacturers that miss the 24-hour early-warning deadline, but it does not remove Article 14 reporting duties.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Prepare an effective request to a CRA reporting helpdesk</title><link>https://actlume.com/blog/cra-sme-reporting-helpdesk/</link><guid isPermaLink="true">https://actlume.com/blog/cra-sme-reporting-helpdesk/</guid><description>The CRA requires coordinating CSIRTs to provide helpdesk support for reporting, with particular attention to microenterprises and small and medium-sized enterprises.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Run a complete CRA reporting readiness exercise</title><link>https://actlume.com/blog/cra-reporting-readiness-exercise/</link><guid isPermaLink="true">https://actlume.com/blog/cra-reporting-readiness-exercise/</guid><description>CRA Article 14 reporting begins on 11 September 2026 and uses separate staged sequences for actively exploited vulnerabilities and severe incidents.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item></channel></rss>