Feature · CRA (EU) 2024/2847

Security & Support: meet the Cyber Resilience Act at the QR code

Vulnerability reporting obligations have applied since 11 September 2026, the full Cyber Resilience Act from 11 December 2027. ManualPass shows support period and security contact at the machine, receives reports and tracks the deadlines.

app.manualpass.eu/p/demobs400Interactive preview

Support period and security contact right at the machine:

ManualPassScan page
Muster Maschinenbau GmbH Band saw BS-400
Security & Support
Security updates until
12/2032
Support
Firmware updates
Security contact
security@muster.example
CVE-2026-12345Firmware 2.4 closes login flaw

The Cyber Resilience Act requires manufacturers not only to make secure products, but also to provide information and processes: customers must see at the time of purchase how long security updates will be provided, vulnerabilities need a point of contact, and actively exploited vulnerabilities must be reported within 24 hours. ManualPass brings this together where your documents already are – at the machine's QR code.

On the scan page: Security & Support

For every machine you mark as a product with digital elements, the scan page shows a dedicated section:

  • Security updates until: end of the support period with month and year.
  • Type of support: for example “Firmware updates via the service portal”.
  • Security contact: your single point of contact for vulnerability reports.
  • Coordinated vulnerability disclosure policy: link to your policy.
  • Report a vulnerability: a form that goes straight to you.
  • Security advisories and updates: all published security updates with CVE ID.

Receiving reports and meeting deadlines

Step What ManualPass does
Report received e-mail to security contact and owners, confirmation with report number to the reporter
Assessment status, affected machine and version, internal notes
Actively exploited deadlines from awareness: early warning 24 h, notification 72 h, final report
Reminder e-mail immediately and daily when a deadline expires within 48 hours or is overdue
Fix publish the security update as an advisory, inform operators

Common misconception

“Reporting obligations only apply from 2027.” The reporting obligations under Article 14 have applied since 11 September 2026 – also for machines already on the market. The remaining requirements follow in December 2027.

Support periods at a glance

In the customer area, you maintain one table for all machine types: whether they have digital elements, until when you provide security updates and what type of support you offer. Machines with digital elements but no support period are flagged, as are support periods ending in less than twelve months.

Practical tip

Upload the user information under Annex II of the CRA – secure commissioning, updates, decommissioning – as a separate document. It is then versioned and available for at least ten years alongside the instructions for use and EU declaration of conformity.

What ManualPass does not do

ManualPass does not submit reports to ENISA or CSIRTs and does not assess the cybersecurity of your machine. It makes sure information is in the right place, reports are not lost and deadlines stay visible. Every step is recorded in the audit log. What the CRA requires in detail is explained in our guide Cyber Resilience Act for machine builders.

Frequently asked questions

Does ManualPass report vulnerabilities to ENISA?

No. You submit reports under Article 14 CRA yourself via ENISA's Single Reporting Platform. ManualPass calculates the deadlines from the moment of awareness, reminds you in good time and records when the early warning, notification and final report were submitted.

Where does the customer see the support period?

On the scan page of every machine you have marked as a product with digital elements – in the “Security & Support” section, together with the type of support, the security contact and the security advisories. The CRA requires the end date to be clearly visible at the time of purchase.

Who can report vulnerabilities?

Anyone – customers, service partners and security researchers – via a form linked from the scan page. The report goes to your security contact and your owners; the reporter receives a confirmation with a report number. The form is protected against spam.

Do I need ManualPass Service for this?

No. Security & Support is included in all plans. With ManualPass Service, you can also send security advisories to your operators by e-mail and prove that they have read them.

Does this make me CRA-compliant?

ManualPass supports the documentation, information and reporting processes. The essential cybersecurity requirements for your machine itself – secure development, updates, SBOM, conformity assessment – remain your responsibility as manufacturer.