Emtract Ingest
API
EN
EN
DE
Dashboard
Regulations
Crawlers
Attributes
Topics
Home
/
Regulations
/
CRA
/
Edit obligation
Edit obligation
Title (English)
Title (German)
Kind
Approval
Due Diligence
Governance
Other
Record Keeping
Reporting
Stakeholder Engagement
Frequency
Annual
Biennial
Continuous
Event-triggered
Monthly
One-time
Other
Quarterly
Weekly
Check frequency
Annual
Biennial
Continuous
Event-triggered
Monthly
One-time
Other
Quarterly
Weekly
Rule set
Regulation-wide (no rule set)
Manufacturers of products with digital elements
Manufacturers of products with digital elements, including products already on the market
Authorised representatives of a manufacturer
Importers of products with digital elements
Distributors of products with digital elements
Economic operators — manufacturers, authorised representatives, importers and distributors
Importers and distributors
Manufacturers of critical products with digital elements
Open-source software stewards
Manufacturers, authorised representatives and importers of products with digital elements
Manufacturers of important products with digital elements, class I
Manufacturers of important products with digital elements, class II
Complexity (0–5)
Business functions
Communications
Compliance
Executive
Finance
Human Resources
Legal
Operations
Other
Procurement
Product
Sales
Sustainability
Description (English)
A manufacturer that becomes aware of an actively exploited vulnerability in its product with digital elements submits an early warning without undue delay and in any event within 24 hours, simultaneously to the CSIRT designated as coordinator and to ENISA through the single reporting platform, stating the Member States in which it knows the product to have been made available. The obligation applies from 11 September 2026, including to products placed on the market before 11 December 2027.
Description (German)
Erlangt ein Hersteller Kenntnis von einer aktiv ausgenutzten Schwachstelle in seinem Produkt mit digitalen Elementen, übermittelt er unverzüglich, in jedem Fall aber innerhalb von 24 Stunden, gleichzeitig dem als Koordinator benannten CSIRT und der ENISA über die einheitliche Meldeplattform eine Frühwarnung. Sie nennt die Mitgliedstaaten, in denen das Produkt seiner Kenntnis nach bereitgestellt wurde. Zuständig ist das als Koordinator benannte CSIRT des Mitgliedstaats der Hauptniederlassung in der Union; ohne Hauptniederlassung in der Union bestimmt es sich in fester Reihenfolge nach dem Bevollmächtigten, dem Einführer, dem Händler und der Zahl der Nutzer. Die Pflicht gilt ab dem 11. September 2026, auch für Produkte, die vor dem 11. Dezember 2027 in den Verkehr gebracht wurden. Verwalter quelloffener Software trifft sie, soweit sie an der Entwicklung der Produkte beteiligt sind.
Affected products/services (English)
All products with digital elements the company makes available on the Union market.
Affected products/services (German)
Alle Produkte mit digitalen Elementen, die das Unternehmen auf dem Unionsmarkt bereitstellt.
Checking responsibility (English)
Product security incident response team or an equivalent function with out-of-hours availability.
Checking responsibility (German)
Product Security Incident Response Team oder eine gleichwertige Stelle mit Rufbereitschaft außerhalb der Geschäftszeiten.
Check method (English)
Notification through the single reporting platform under Article 16 to the electronic endpoint of the competent CSIRT, with a documented timestamp of becoming aware.
Check method (German)
Meldung über die einheitliche Meldeplattform nach Artikel 16 an den elektronischen Meldeendpunkt des zuständigen CSIRT, mit dokumentiertem Zeitstempel der Kenntniserlangung.
Withdrawn at
Cancel
Delete this obligation