A report comes in — you know what happens
A report can come from a customer, a procurement questionnaire or a researcher. In Kunnus it has a route from the first minute: intake, assessment, the early warning, the advisory. And the reporter stays in the loop.
The reporting obligations of the EU Cyber Resilience Act apply since 11 September 2026 — including for the machines, devices and software already sitting at your customers' sites by then. See the deadlines
Early warning within 24 hours and notification within 72 hours of awareness. The final report is due no later than 14 days after a corrective measure is available for an actively exploited vulnerability, and no later than one month after the notification for a severe incident (Art. 14 of the EU Cyber Resilience Act).
The route of a report through Kunnus
Kunnus brings the whole Cyber Resilience Act reporting process with it and supports you at each of the four stations, from intake to evidence.
Intake
The report arrives through your public form, out of the vulnerability workflow, or by hand. Kunnus acknowledges it; the tracking ID goes to the reporter, the notification to your team.
Go to sectionTriage
Two clocks run visibly on the case. You pick the affected products from your inventory and set the ownership — the judgement is yours.
Go to sectionFiling
Kunnus derives the deadline from the awareness moment, asks for what ENISA's Single Reporting Platform wants answered, and produces the structured export.
Go to sectionCommunication & evidence
Kunnus writes the advisory in CSAF format, keeps the reporter updated automatically and files every change as evidence.
Go to section14:11 · The report arrives
A report arrives and your team knows right away
The route starts outside your company: a customer, a researcher or an operator fills in your public report form. From there Kunnus works. The report is acknowledged, gets a tracking ID and lands in your team's queue.
- A public form on a shareable URL, with no account for the reporter
- Acknowledgement and tracking ID go out on their own. The reporter checks the status whenever they want
- Kunnus notifies your team proactively; nobody has to watch a mailbox
Every report lands in one queue, with severity, status and the Cyber Resilience Act deadlines attached to it.
13 hours left to the acknowledgement
Five stages, two clocks
A disclosure moves through five stages in Kunnus, from received to disclosed. Two of them carry a commitment to the reporter: the acknowledgement and the assessment. Both show how much time is left — and Kunnus speaks up before a deadline slips.
- Progress is readable without anyone chasing a status update
- Open deadlines show as hours left on the case; Kunnus warns before they run out
- You pick the affected products from your inventory — product lines and firmware builds are already there
Kunnus tracks the Cyber Resilience Act requirements on the case and stores every step with a timestamp, so you can prove later that you met them.
Read it in the legal text — Art. 1420 hours left to the early warning
The process comes with it — or fits into yours
You do not have to invent a reporting process or replace the one you run: Kunnus brings the sequence with it. At the end there is a structured export that goes into the platform as-is.
Guided, not an empty form
The case asks in order for what the filing carries. Whatever Kunnus already holds is prefilled — you are only asked for what is genuinely new.
The awareness moment is captured automatically
You confirm the active exploitation or the severe incident — Kunnus generates the reporting case, sets the timestamp and starts the 24 hours from that moment.
It meets what you already run
If you already run a PSIRT, a ticketing system or an approval route, you keep it. Kunnus attaches where the deadline, the field set and the evidence come into being.
The case is built on the details ENISA's Single Reporting Platform asks for at each stage. How a specific incident is classified under the Cyber Resilience Act remains your call; Kunnus records how it was made.
Read it in the legal text — Art. 14Handled — now the news goes out
Communication and evidence come out of the same record
Once the vulnerability is handled, the outward-facing work remains: the security advisory, the reply to the reporter, the notice to your customers — and the evidence in case someone checks under the Cyber Resilience Act. In Kunnus all of it comes out of the case itself, captured once.
- The security advisory can be created straight from the case — in CSAF format, machine-readable instead of a PDF in a downloads folder
- The reporter is kept up to date automatically; the tracking ID shows them where it stands
- You inform affected customers directly from the 72-hour notification on (Art. 14(8)); the email templates are ready and the facts come from the case
- If the CSIRT asks for an interim report (Art. 14(6)), it is an export from the history, not a reconstruction
- Every field change sits in the history with a timestamp and an author, exportable as evidence
We run Kunnus on Kunnus: our own disclosure portal and our CSAF feed run on the platform. See our own disclosure page
Three views of the same case
A report under the Cyber Resilience Act occupies more than one person. Kunnus shows everyone the slice they work with — nobody compiles reports on the side.
Product compliance & PSIRT
Works the case: triage, fields, advisory. Kunnus asks for the required details in order.
Head of Product Security / CISO
Sees deadlines and status across all open cases without calling a status round.
Management & audit
Gets the record: who decided what and when, exportable from the case.
The process is in place before the first report arrives
None of this has to be built in the middle of your first live case. The Cyber Resilience Act asks for three things, and they stand in Kunnus from day one:
- Your public intake point: the report form on a shareable URL — ready for security.txt, your website and your contracts
- A coordinated vulnerability disclosure policy from the template library
- Your SLAs for acknowledgement and triage, configured with deadlines that run on their own and warn in time
Industries
Built for everyone who ships
The trigger is the same in every industry: someone outside your company finds something. Kunnus brings the route, the deadlines and the record it takes from there.

Industrial Machinery
One component, a whole product line affected.

IoT & Consumer Products
Many SKUs, many reports. Triage with a clock.

Energy & Building Tech
Operators ask about your reporting route in procurement.

Industrial Components
The OEM files and needs your input within hours.

Smart Farming
In season the report arrives outside office hours.

Telecom & Networking
Advisories your customers ingest machine-to-machine.

Software & SaaS
Researchers already report. Now with a defined route.

Embedded Systems
From the CVE to the affected firmware build.

Smart Home & Consumer
Support and the public, one intake point.
Common questions about the reporting obligations
Does this apply to products we shipped years ago?
Yes. The reporting obligations of the EU Cyber Resilience Act apply from 11 September 2026, and they reach products with digital elements that are already on the market at that date. For a machine with a 15-year service life that means the installed base counts. In Kunnus it lives in the product inventory, so a report finds the affected legacy products as readily as the current line.
Does Kunnus file the report with ENISA?
You submit in the Single Reporting Platform yourself. Kunnus prepares the filing: the case asks for exactly the details the platform wants at each stage and turns them into a structured export you can submit as-is.
Who files when we supply a component to an OEM?
The obligation under the EU Cyber Resilience Act sits with the manufacturer of the product with digital elements — whoever places it on the market under their own name or trademark. As a supplier you feed that filing in practice: affected versions, remediation status, advisory. In Kunnus you run your own cases for your own products; for the input to the OEM, the advisory and email templates are at hand. How the roles fall in your specific contract is your call.
We have no reporting process yet. What is the minimum?
Three things: a reachable address where vulnerabilities can be reported, a coordinated vulnerability disclosure policy, and a way to share information about handled vulnerabilities. In Kunnus those are a public report form with a tracking ID, a template from the policy library, and security advisories in CSAF format.
Do we need a bug bounty programme for this?
No. What is asked for is a route on which reports arrive and get worked, not a reward. A bug bounty programme can sit on top of that, but it does not replace it: the basis is a reachable intake point, an acknowledgement, an assessment with a deadline, and a reply to the reporter. Kunnus ships with all four already in place.
What happens if a report arrives at night or during a shutdown?
Intake is captured and acknowledged immediately, your team is notified, and the SLA for acknowledgment and triage runs visibly from that moment. The early-warning deadline hangs on a different moment: 24 hours after awareness, from 11 September 2026 — meaning the point at which an authorised person established reasonable certainty that exploitation is active. In Kunnus that moment is its own documented field on the case.
Related features
Vulnerability management
Detection, triage and remediation — the foundation every report is built on.
OpenEvidence & compliance
Every report and every advisory becomes part of the audit-ready record.
OpenRisk analysis & threat modelling
What incidents teach flows back into the product risk assessment.
OpenLast reviewed: · Based on the EU Cyber Resilience Act. This page is orientation, not legal advice.
Watch a report run through Kunnus
In a personal demo we walk the Cyber Resilience Act sequence on a real case — from the incoming report through to the advisory.
30 minutes, no preparation needed on your side.