The Cyber Resilience Act requires manufacturers not only to make secure products, but also to provide information and processes: customers must see at the time of purchase how long security updates will be provided, vulnerabilities need a point of contact, and actively exploited vulnerabilities must be reported within 24 hours. ManualPass brings this together where your documents already are – at the machine's QR code.
On the scan page: Security & Support
For every machine you mark as a product with digital elements, the scan page shows a dedicated section:
- Security updates until: end of the support period with month and year.
- Type of support: for example “Firmware updates via the service portal”.
- Security contact: your single point of contact for vulnerability reports.
- Coordinated vulnerability disclosure policy: link to your policy.
- Report a vulnerability: a form that goes straight to you.
- Security advisories and updates: all published security updates with CVE ID.
Receiving reports and meeting deadlines
| Step | What ManualPass does |
|---|---|
| Report received | e-mail to security contact and owners, confirmation with report number to the reporter |
| Assessment | status, affected machine and version, internal notes |
| Actively exploited | deadlines from awareness: early warning 24 h, notification 72 h, final report |
| Reminder | e-mail immediately and daily when a deadline expires within 48 hours or is overdue |
| Fix | publish the security update as an advisory, inform operators |
Common misconception
“Reporting obligations only apply from 2027.” The reporting obligations under Article 14 have applied since 11 September 2026 – also for machines already on the market. The remaining requirements follow in December 2027.
Support periods at a glance
In the customer area, you maintain one table for all machine types: whether they have digital elements, until when you provide security updates and what type of support you offer. Machines with digital elements but no support period are flagged, as are support periods ending in less than twelve months.
Practical tip
Upload the user information under Annex II of the CRA – secure commissioning, updates, decommissioning – as a separate document. It is then versioned and available for at least ten years alongside the instructions for use and EU declaration of conformity.
What ManualPass does not do
ManualPass does not submit reports to ENISA or CSIRTs and does not assess the cybersecurity of your machine. It makes sure information is in the right place, reports are not lost and deadlines stay visible. Every step is recorded in the audit log. What the CRA requires in detail is explained in our guide Cyber Resilience Act for machine builders.
Frequently asked questions
Does ManualPass report vulnerabilities to ENISA?
No. You submit reports under Article 14 CRA yourself via ENISA's Single Reporting Platform. ManualPass calculates the deadlines from the moment of awareness, reminds you in good time and records when the early warning, notification and final report were submitted.
Where does the customer see the support period?
On the scan page of every machine you have marked as a product with digital elements – in the “Security & Support” section, together with the type of support, the security contact and the security advisories. The CRA requires the end date to be clearly visible at the time of purchase.
Who can report vulnerabilities?
Anyone – customers, service partners and security researchers – via a form linked from the scan page. The report goes to your security contact and your owners; the reporter receives a confirmation with a report number. The form is protected against spam.
Do I need ManualPass Service for this?
No. Security & Support is included in all plans. With ManualPass Service, you can also send security advisories to your operators by e-mail and prove that they have read them.
Does this make me CRA-compliant?
ManualPass supports the documentation, information and reporting processes. The essential cybersecurity requirements for your machine itself – secure development, updates, SBOM, conformity assessment – remain your responsibility as manufacturer.