Determine applicability first
Inventory digital products, the company's role and the markets where each product is supplied. An organization may be a manufacturer, importer, distributor or component supplier, and the duties differ. Record a legally reviewed conclusion for each product instead of relying on a blanket statement that CRA does not apply.
Map each product to an owner, repositories, component inventory, update channel and support contacts. This is what allows a team to identify affected versions and customers quickly.
Separate detection from qualification
A signal may arrive from a researcher, customer, CERT, dependency scanner or operations. One intake records the time, product, version and available evidence. An assigned group then decides whether the issue is an actively exploited vulnerability or a severe incident under the applicable criteria.
Technical uncertainty does not stop the clock. Record the decision, rationale and known facts from the beginning and update them during investigation.
Prepare the 24- and 72-hour packages
From 11 September 2026, an early warning for covered events is due within 24 hours and a fuller notification within 72 hours. Templates should name the submitter and backup, required facts, legal review path and procedure for the single reporting platform.
Reporting does not replace remediation. In parallel, contain impact, build and test an update, and communicate with affected customers through an agreed channel.
Rehearse the end-to-end process
Start an exercise with an ambiguous support email rather than a ready-made CVE. Test whether the front line recognizes the signal, the team finds the SBOM, affected versions are identified and decision makers meet deadlines outside office hours.
CRA may matter to non-EU companies when relevant products are placed on the European market. Confirm legal applicability and notification wording with qualified counsel, while preparing the technical workflow in advance.

