Glossary
The Cyber Resilience Act, term by term.
50 definitions written for engineering, security and compliance leads: what the term means, where it sits in Regulation (EU) 2024/2847 and which Vellaci workflow operationalises it. Paraphrases, not legal advice.
- 72-hour notification
- The second Article 14 stage, due within 72 hours of awareness, with general product information, an initial assessment and measures taken.
- Art. 14(2)(b) and 14(4)(b)
- Actively exploited vulnerability
- A vulnerability for which there is reliable evidence that malicious code was executed on a system without the owner's permission — the trigger for Article 14 reporting.
- Art. 3(42); Art. 14(1)–(3)
- Authorised representative
- An EU-established party mandated in writing by a non-EU manufacturer to act on its behalf for specified CRA tasks.
- Art. 3 (definition); Art. 18
- Awareness (becoming aware)
- The moment the manufacturer has sufficient information to conclude that an exploited vulnerability or severe incident exists — the start of every Article 14 clock.
- Art. 14(2) and 14(4)
- CE marking
- The visible marking indicating conformity with all applicable Union harmonisation legislation, including the CRA from 11 December 2027.
- Art. 29–30
- Conformity assessment
- The procedure demonstrating that a product meets the essential requirements — internal control, EU-type examination or full quality assurance — before CE marking.
- Art. 32; Annex VIII
- Coordinated vulnerability disclosure (CVD)
- A published policy and process for receiving vulnerability reports from third parties and fixing and disclosing them in coordination — required by Annex I Part II.
- Annex I Part II(5)–(6); ISO/IEC 29147; RFC 9116
- Core functionality
- The test that decides whether an Annex III or IV category applies: the listed function must be the product's core purpose, not an incidental feature.
- Art. 7(1); Art. 8(1)
- Corrective or mitigating measure
- A security update or other action that removes or reduces an exploited vulnerability; its availability starts the 14-day final-report timer.
- Art. 14(2)(c)
- Critical product with digital elements
- A product in an Annex IV category for which the Commission may mandate European cybersecurity certification.
- Art. 8; Annex IV
- CSIRT designated as coordinator
- The national computer security incident response team designated by each Member State to receive CRA notifications and coordinate.
- Art. 14(7); Art. 16
- CVSS (Common Vulnerability Scoring System)
- The standard 0–10 severity score for vulnerabilities, describing technical impact rather than exploitation likelihood.
- FIRST CVSS v3.1 and v4.0
- Cyber Resilience Act (CRA)
- EU regulation setting cybersecurity requirements for products with digital elements placed on the EU market, including vulnerability handling and incident reporting.
- Regulation (EU) 2024/2847, Art. 1 and Art. 71
- Cybersecurity risk assessment
- The documented assessment of a product's cybersecurity risks that drives which essential requirements apply and how.
- Art. 13(2)–(3); Annex VII(3)
- CycloneDX
- An OWASP-originated, ECMA-standardised SBOM and VEX format widely used in application-security tooling.
- OWASP CycloneDX specification; ECMA-424
- Distributor
- A supply-chain party other than the manufacturer or importer that makes a product available on the market without affecting its properties.
- Art. 3 (definitions); obligations in Art. 20
- Early warning
- The first Article 14 notification, due within 24 hours of awareness, indicating the event and, where applicable, the Member States concerned.
- Art. 14(2)(a) and 14(4)(a)
- EPSS (Exploit Prediction Scoring System)
- A FIRST-maintained daily probability (0–1) that a CVE will be exploited in the wild in the next 30 days.
- FIRST EPSS
- Essential cybersecurity requirements
- Annex I requirements on product properties (Part I) and on vulnerability handling (Part II) that every product must meet.
- Art. 6 and Annex I
- EU declaration of conformity
- The manufacturer's formal statement that a product meets the CRA's essential requirements, accompanying the CE marking.
- Art. 28; Annex V
- Final report
- The last Article 14 stage: 14 days after a corrective measure for vulnerabilities, one month after the notification for incidents.
- Art. 14(2)(c) and 14(4)(c)
- Harmonised standard
- A European standard adopted on Commission request and cited in the Official Journal; full application gives a presumption of conformity.
- Art. 27–28
- IEC 62443
- The international standard series for security of industrial automation and control systems, frequently mapped to CRA requirements by OT manufacturers.
- IEC 62443-4-1 and 62443-4-2
- Important product with digital elements
- A product whose core functionality is listed in Annex III (Class I or Class II), subject to stricter conformity assessment.
- Art. 7; Annex III; Art. 32(2)–(3)
- Importer
- An EU-established party that places on the market a product from a manufacturer established outside the EU.
- Art. 3 (definitions); obligations in Art. 19
- Incident
- An event compromising the availability, authenticity, integrity or confidentiality of data or of the services offered by network and information systems.
- Art. 3(43), referring to Directive (EU) 2022/2555
- Known Exploited Vulnerabilities (KEV) catalogue
- CISA's public list of CVEs with confirmed exploitation in the wild — strong evidence for the CRA's 'actively exploited' test.
- CISA KEV catalogue
- Main establishment
- The Member State where decisions on the manufacturer's cybersecurity are predominantly taken — determines the competent coordinator CSIRT.
- Art. 14(7)
- Manufacturer
- The party that develops or has developed a product with digital elements and markets it under its own name or trademark.
- Art. 3(13); obligations in Art. 13–14
- Market surveillance authority
- The national authority that checks CRA compliance, requests documentation and can order corrective action or withdrawal.
- Art. 52–63; penalties Art. 64
- NIS2 Directive
- Directive (EU) 2022/2555 on cybersecurity of essential and important entities — regulates organisations, whereas the CRA regulates products.
- Directive (EU) 2022/2555
- Notified body
- A conformity assessment body designated by a Member State and notified to the Commission to perform third-party CRA assessments.
- Art. 35–51; Art. 71(2)
- Open-source software steward
- A legal person that systematically supports the development of open-source products intended for commercial activities, without being their manufacturer.
- Art. 3(14); obligations in Art. 24
- OSV (Open Source Vulnerabilities)
- Google's open, purl-indexed database and API aggregating vulnerability advisories across open-source ecosystems.
- osv.dev
- Package URL (purl)
- A standard identifier for a software package across ecosystems, used to match SBOM components against vulnerability databases reliably.
- purl specification (package-url/purl-spec)
- Placing on the market
- The first making available of a product with digital elements on the Union market.
- Art. 3 (definitions of making available and placing on the market)
- Product with digital elements
- Any software or hardware product and its remote data processing solutions, including components placed on the market separately.
- Art. 3(1); exclusions in Art. 2
- Remote data processing
- Data processing at a distance designed by the manufacturer, without which the product could not perform one of its functions.
- Art. 3(2)
- Security update
- An update whose main purpose is to fix vulnerabilities; must be provided free of charge, promptly and securely during the support period.
- Art. 3 (definition of security update); Annex I Part II(7)–(8)
- security.txt
- A standard text file at /.well-known/security.txt telling researchers how to report vulnerabilities (RFC 9116).
- RFC 9116
- Severe incident having an impact on the security of the product
- An incident that negatively affects the product's ability to protect sensitive data or functions, or introduces malicious code — reportable under Article 14.
- Art. 3(45); Art. 14(4)–(5)
- Single reporting platform (SRP)
- The ENISA-operated platform through which manufacturers submit Article 14 notifications to the coordinating CSIRT and ENISA simultaneously.
- Art. 14(1); Art. 16
- Software bill of materials (SBOM)
- A machine-readable inventory of the software components a product contains, required by the CRA at least for top-level dependencies.
- Art. 3 (definition); Annex I Part II(1); Annex VII
- SPDX
- The Linux Foundation's SBOM standard, published as ISO/IEC 5962, common in licence compliance and distribution workflows.
- ISO/IEC 5962:2021; SPDX specification
- Substantial modification
- A change after placing on the market that affects compliance with the essential requirements or changes the intended purpose.
- Art. 3 (definition of substantial modification); Art. 13
- Support period
- The manufacturer-defined period, normally at least five years, during which vulnerabilities are handled and security updates are provided.
- Art. 13(8)–(9)
- Technical documentation (Annex VII)
- The documentation a manufacturer must draw up before placing a product on the market and keep for at least ten years.
- Art. 31 and Annex VII; retention Art. 13(13)
- VEX (Vulnerability Exploitability eXchange)
- VEX, or Vulnerability Exploitability eXchange, is a machine-readable statement of whether a known vulnerability affects a specific product and why.
- CISA minimum requirements for VEX; CycloneDX VEX specification
- Vulnerability
- A weakness, susceptibility or flaw in a product that can be exploited by a cyber threat.
- Art. 3(40)–(42)
- Vulnerability handling
- The Annex I Part II process requirements: identify, remediate, test, disclose, coordinate, share and update — for the whole support period.
- Annex I Part II; Art. 13(8)
From definitions to operations.
Every term above maps to a record, a workflow or a deadline in Vellaci.