Glossary

The Cyber Resilience Act, term by term.

50 definitions written for engineering, security and compliance leads: what the term means, where it sits in Regulation (EU) 2024/2847 and which Vellaci workflow operationalises it. Paraphrases, not legal advice.

72-hour notification
The second Article 14 stage, due within 72 hours of awareness, with general product information, an initial assessment and measures taken.
Art. 14(2)(b) and 14(4)(b)
Actively exploited vulnerability
A vulnerability for which there is reliable evidence that malicious code was executed on a system without the owner's permission — the trigger for Article 14 reporting.
Art. 3(42); Art. 14(1)–(3)
Authorised representative
An EU-established party mandated in writing by a non-EU manufacturer to act on its behalf for specified CRA tasks.
Art. 3 (definition); Art. 18
Awareness (becoming aware)
The moment the manufacturer has sufficient information to conclude that an exploited vulnerability or severe incident exists — the start of every Article 14 clock.
Art. 14(2) and 14(4)
CE marking
The visible marking indicating conformity with all applicable Union harmonisation legislation, including the CRA from 11 December 2027.
Art. 29–30
Conformity assessment
The procedure demonstrating that a product meets the essential requirements — internal control, EU-type examination or full quality assurance — before CE marking.
Art. 32; Annex VIII
Coordinated vulnerability disclosure (CVD)
A published policy and process for receiving vulnerability reports from third parties and fixing and disclosing them in coordination — required by Annex I Part II.
Annex I Part II(5)–(6); ISO/IEC 29147; RFC 9116
Core functionality
The test that decides whether an Annex III or IV category applies: the listed function must be the product's core purpose, not an incidental feature.
Art. 7(1); Art. 8(1)
Corrective or mitigating measure
A security update or other action that removes or reduces an exploited vulnerability; its availability starts the 14-day final-report timer.
Art. 14(2)(c)
Critical product with digital elements
A product in an Annex IV category for which the Commission may mandate European cybersecurity certification.
Art. 8; Annex IV
CSIRT designated as coordinator
The national computer security incident response team designated by each Member State to receive CRA notifications and coordinate.
Art. 14(7); Art. 16
CVSS (Common Vulnerability Scoring System)
The standard 0–10 severity score for vulnerabilities, describing technical impact rather than exploitation likelihood.
FIRST CVSS v3.1 and v4.0
Cyber Resilience Act (CRA)
EU regulation setting cybersecurity requirements for products with digital elements placed on the EU market, including vulnerability handling and incident reporting.
Regulation (EU) 2024/2847, Art. 1 and Art. 71
Cybersecurity risk assessment
The documented assessment of a product's cybersecurity risks that drives which essential requirements apply and how.
Art. 13(2)–(3); Annex VII(3)
CycloneDX
An OWASP-originated, ECMA-standardised SBOM and VEX format widely used in application-security tooling.
OWASP CycloneDX specification; ECMA-424
Distributor
A supply-chain party other than the manufacturer or importer that makes a product available on the market without affecting its properties.
Art. 3 (definitions); obligations in Art. 20
Early warning
The first Article 14 notification, due within 24 hours of awareness, indicating the event and, where applicable, the Member States concerned.
Art. 14(2)(a) and 14(4)(a)
EPSS (Exploit Prediction Scoring System)
A FIRST-maintained daily probability (0–1) that a CVE will be exploited in the wild in the next 30 days.
FIRST EPSS
Essential cybersecurity requirements
Annex I requirements on product properties (Part I) and on vulnerability handling (Part II) that every product must meet.
Art. 6 and Annex I
EU declaration of conformity
The manufacturer's formal statement that a product meets the CRA's essential requirements, accompanying the CE marking.
Art. 28; Annex V
Final report
The last Article 14 stage: 14 days after a corrective measure for vulnerabilities, one month after the notification for incidents.
Art. 14(2)(c) and 14(4)(c)
Harmonised standard
A European standard adopted on Commission request and cited in the Official Journal; full application gives a presumption of conformity.
Art. 27–28
IEC 62443
The international standard series for security of industrial automation and control systems, frequently mapped to CRA requirements by OT manufacturers.
IEC 62443-4-1 and 62443-4-2
Important product with digital elements
A product whose core functionality is listed in Annex III (Class I or Class II), subject to stricter conformity assessment.
Art. 7; Annex III; Art. 32(2)–(3)
Importer
An EU-established party that places on the market a product from a manufacturer established outside the EU.
Art. 3 (definitions); obligations in Art. 19
Incident
An event compromising the availability, authenticity, integrity or confidentiality of data or of the services offered by network and information systems.
Art. 3(43), referring to Directive (EU) 2022/2555
Known Exploited Vulnerabilities (KEV) catalogue
CISA's public list of CVEs with confirmed exploitation in the wild — strong evidence for the CRA's 'actively exploited' test.
CISA KEV catalogue
Main establishment
The Member State where decisions on the manufacturer's cybersecurity are predominantly taken — determines the competent coordinator CSIRT.
Art. 14(7)
Manufacturer
The party that develops or has developed a product with digital elements and markets it under its own name or trademark.
Art. 3(13); obligations in Art. 13–14
Market surveillance authority
The national authority that checks CRA compliance, requests documentation and can order corrective action or withdrawal.
Art. 52–63; penalties Art. 64
NIS2 Directive
Directive (EU) 2022/2555 on cybersecurity of essential and important entities — regulates organisations, whereas the CRA regulates products.
Directive (EU) 2022/2555
Notified body
A conformity assessment body designated by a Member State and notified to the Commission to perform third-party CRA assessments.
Art. 35–51; Art. 71(2)
Open-source software steward
A legal person that systematically supports the development of open-source products intended for commercial activities, without being their manufacturer.
Art. 3(14); obligations in Art. 24
OSV (Open Source Vulnerabilities)
Google's open, purl-indexed database and API aggregating vulnerability advisories across open-source ecosystems.
osv.dev
Package URL (purl)
A standard identifier for a software package across ecosystems, used to match SBOM components against vulnerability databases reliably.
purl specification (package-url/purl-spec)
Placing on the market
The first making available of a product with digital elements on the Union market.
Art. 3 (definitions of making available and placing on the market)
Product with digital elements
Any software or hardware product and its remote data processing solutions, including components placed on the market separately.
Art. 3(1); exclusions in Art. 2
Remote data processing
Data processing at a distance designed by the manufacturer, without which the product could not perform one of its functions.
Art. 3(2)
Security update
An update whose main purpose is to fix vulnerabilities; must be provided free of charge, promptly and securely during the support period.
Art. 3 (definition of security update); Annex I Part II(7)–(8)
security.txt
A standard text file at /.well-known/security.txt telling researchers how to report vulnerabilities (RFC 9116).
RFC 9116
Severe incident having an impact on the security of the product
An incident that negatively affects the product's ability to protect sensitive data or functions, or introduces malicious code — reportable under Article 14.
Art. 3(45); Art. 14(4)–(5)
Single reporting platform (SRP)
The ENISA-operated platform through which manufacturers submit Article 14 notifications to the coordinating CSIRT and ENISA simultaneously.
Art. 14(1); Art. 16
Software bill of materials (SBOM)
A machine-readable inventory of the software components a product contains, required by the CRA at least for top-level dependencies.
Art. 3 (definition); Annex I Part II(1); Annex VII
SPDX
The Linux Foundation's SBOM standard, published as ISO/IEC 5962, common in licence compliance and distribution workflows.
ISO/IEC 5962:2021; SPDX specification
Substantial modification
A change after placing on the market that affects compliance with the essential requirements or changes the intended purpose.
Art. 3 (definition of substantial modification); Art. 13
Support period
The manufacturer-defined period, normally at least five years, during which vulnerabilities are handled and security updates are provided.
Art. 13(8)–(9)
Technical documentation (Annex VII)
The documentation a manufacturer must draw up before placing a product on the market and keep for at least ten years.
Art. 31 and Annex VII; retention Art. 13(13)
VEX (Vulnerability Exploitability eXchange)
VEX, or Vulnerability Exploitability eXchange, is a machine-readable statement of whether a known vulnerability affects a specific product and why.
CISA minimum requirements for VEX; CycloneDX VEX specification
Vulnerability
A weakness, susceptibility or flaw in a product that can be exploited by a cyber threat.
Art. 3(40)–(42)
Vulnerability handling
The Annex I Part II process requirements: identify, remediate, test, disclose, coordinate, share and update — for the whole support period.
Annex I Part II; Art. 13(8)

From definitions to operations.

Every term above maps to a record, a workflow or a deadline in Vellaci.