Reporting of exploited vulnerabilities and severe incidents (Articles 14 and 15) – EU Cyber Resilience Act
EU Cyber Resilience Act Art. 14(6): Intermediate reports on request
Where the coordinating CSIRT asks, the manufacturer must provide an intermediate report with relevant status updates on the exploited vulnerability or severe incident.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.