EU CRA Obligations from 11 September
The CRA introduces a reporting obligation as early as 11 September 2026, which we would like to take a closer look at here.
What must be reported?
Actively exploited vulnerabilities
– or severe security incidents affecting product security
must be reported to ENISA via the Single Reporting Platform (SRP). The report is then automatically forwarded to the relevant national CSIRT – in Austria, CERT.at.
Deadlines
Within 24 hours: An early warning must be submitted after becoming aware of the vulnerability.
– Within 72 hours: A more detailed notification must be submitted, including the nature and scope of the vulnerability, an initial assessment, and possible mitigation measures.
– Within 14 days after a fix or mitigation measure becomes available, a final report must be submitted.
– In the event of a severe security incident, a detailed report must be submitted within one month.
– User notification obligation: Affected users must be informed without undue delay.
User Notification Obligation
Since 2024, we have regularly published Security Advisories on our website, documenting identified and resolved vulnerabilities.
– https://www.iacbox.com/wissen/security-advisories/
Reporting Vulnerabilities to Us
In addition to the mandatory reporting of security vulnerabilities and incidents, we have now officially established a PSIRT (Product Security Incident Response Team) responsible for vulnerability management.
You can contact our Security Team at any time via security@iacbox.com. For critical security incidents or vulnerabilities, we kindly ask you to use PGP encryption.
– Our website now also provides a security.txt file: https://www.iacbox.com/.well-known/security.txt
– PGP Key: https://www.iacbox.com/.well-known/security-pub.asc
Vulnerability Disclosure Policy
We have published a Vulnerability Disclosure Policy (VDP) describing our preferred Coordinated Vulnerability Disclosure (CVD) process. This gives us the opportunity to address vulnerabilities before they are publicly disclosed, while also defining a clear timeline within which we will respond.
– https://www.iacbox.com/iacbox-vdp.txt
Vulnerability Management
The IACBOX development team has been managing vulnerabilities for many years, particularly those affecting third-party dependencies used in our products. As part of our CRA compliance efforts, we have further expanded and formalised this process.
We produce SBOMs (Software Bills of Materials) for our software products in order to identify vulnerabilities within our software supply chain quickly and efficiently. Although the SBOM requirement will not become mandatory until 2027, SBOMs have already been an integral part of our software development process for some time, as they are essential for effective vulnerability management.
Contact
Stay secure and up to date with IACBOX Software Maintenance! If you require any further information, please contact us.