Vulnerability Reporting – CRA

Cyber Resilience Act: vulnerability reporting obligations take effect

From 11 September 2026, the reporting obligations set out in Article 14 of the Cyber Resilience Act (Regulation (EU) 2024/2847) apply. This European legislation introduces new cybersecurity requirements for products with digital elements.

The Regulation is due to apply in full from December 2027; however, manufacturers are already required to manage and notify the competent authorities of actively exploited vulnerabilities and any security incidents that may have a significant impact on their products.

How ELCA is preparing

ELCA has begun taking the necessary steps to comply with the requirements introduced by the Cyber Resilience Act.

This commitment covers both company processes and the products themselves, which are being progressively analysed and updated to ensure compliance with the security requirements laid down by the legislation.

Vulnerability Reporting – CRA

Customers, partners and users can report potential security issues to ELCA at cybersecurity@elcaradio.com, including vulnerabilities, unusual behaviour or other issues relating to the cybersecurity of its products.

Reports will be assessed by qualified technical staff to identify corrective actions quickly and help continuously improve the security and reliability of ELCA products.

For more information on how to submit a report, the vulnerability management process and the rules applying to reporters, please consult the Vulnerability Disclosure Policy (PDF, opens in a new tab) adopted by ELCA for managing reports.