Clearlane
Guide · 6 min read

Cyber Resilience Act: how to handle vulnerability reporting in Jira

Since 11 September 2026, manufacturers of products with digital elements sold in the EU must report actively exploited vulnerabilities and severe incidents within hours, not weeks. Most software teams already track vulnerabilities in Jira. Here is what the Cyber Resilience Act adds, and how to keep the deadlines from your work items.

What Article 14 asks for

The Cyber Resilience Act (Regulation (EU) 2024/2847) applies in two steps: the reporting obligations of Article 14 from 11 September 2026, the rest of the regulation from 11 December 2027. Reporting also covers products already on the market. Two events must be reported to the national CSIRT and ENISA, through ENISA’s Single Reporting Platform:

  • An actively exploited vulnerability in your product.
  • A severe incident that affects the security of your product.

The three deadlines

They all start when you become aware of the event, so that moment must be recorded.

  1. Early warning: 24 hours. A short notice that the event exists.
  2. Notification: 72 hours. What you know, its severity and the first measures.
  3. Final report. For a vulnerability, at the latest 14 days after a fix or mitigation is available. For a severe incident, one month after the notification.

You must also inform the users of the product, and publish a security advisory once a fix exists.

What Jira already gives you

Scanners such as Snyk, Dependabot, Mend or Trivy create work items with the package, the CVE and a severity. That covers detection. It does not tell you whether the vulnerability is reportable, when the 24-hour clock started, which of your products and versions contain the component, or what you sent to ENISA and when.

Mistakes to avoid

  • No recorded moment of awareness. Without it, nobody can show the deadlines were kept.
  • Not knowing where a component is used. Keep an SBOM for each version on the market, so you can answer in minutes.
  • Reports written from memory. Prepare them from the record, and keep the reference ENISA gives you.
  • Evidence spread across e-mails and chats. The regulation expects the technical documentation, reports included, to be kept for at least ten years.

Step by step with Clearlane CRA

  1. Open the CRA panel on the scanner’s work item. The package, CVE and affected range are read from it, and the products whose SBOM contains the component are proposed.
  2. Qualify the case with a signature: actively exploited or not, and when you became aware of it. The three clocks start.
  3. Copy the prepared fields into ENISA’s platform, then record when you submitted and the reference you received. The app never submits anything on your behalf.
  4. Record the fix, the notice to users and the advisory, with a CSAF file attached to the work item.
  5. Close the case with a signature and keep the PDF evidence file with your technical documentation.

Clearlane CRA helps manufacturers meet the reporting requirements of the Cyber Resilience Act; your own assessment still applies. See how Clearlane CRA works →