Knowledge

Knowledge

CRA: your new security feed

CRA: your new security feed

Tacit becomes a CNA
Tacit becomes a CNA

From September 11, manufacturers must report certain security events to regulators and inform impacted users too.

Most CRA readiness discussions focus on reporting to ENISA and the designated CSIRT: the Single Reporting Platform, the 24-hour early warning and the 72-hour notification. But Article 14, which applies from September 11, 2026, also creates a direct obligation toward users. For software customers, this means something very concrete: you should receive security information directly from your vendors when the products you rely on are affected.

When you're impacted, your vendor must tell you

When a manufacturer becomes aware of an actively exploited vulnerability or a severe incident affecting the security of its product, reporting to authorities is only part of the workflow.

Under Article 14(8), the manufacturer must also inform impacted users, and, where appropriate, all users, about the vulnerability or incident. Where necessary, that communication must include the mitigation or corrective measures users can take. The CRA even anticipates structured, machine-readable communication where appropriate.

This user communication runs alongside regulatory reporting. Sending the required notification to ENISA does not remove the obligation to inform customers.

For security teams buying and operating third-party software, this matters. Your vendors are becoming an additional source of security intelligence about the products in your environment.

Track how vendors respond

Receiving more vendor notifications is only the starting point.

Security information is already fragmented across vendor advisories, support portals, emails, CVE records and findings from scanners or vulnerability operations teams. The CRA increases the amount of vendor-originated information available to customers. Tacit helps reconcile that information with signals coming from scanners and VOC teams.

When a new vulnerability appears, the real questions are often not “Have we seen a CVE?” but:

Does it affect the product and version we use? Has the vendor assessed it? When did they communicate their position? Is there a mitigation or update available? How does that compare with what our own tools are telling us?

The CRA makes those questions increasingly relevant.

With Tacit, vendor security communication becomes something you can track over time: time to vendor position, time to customer notification, affected products and versions, available mitigations, remediation status, or vulnerability signals that remain unanswered.

These metrics create a new way to verify whether vendors are meeting the security commitments defined in your contracts and internal security policies, based on their actual response to security events.

Tacit is built around that signal. It centralizes security communication at product and version level, notifies customers when new vendor information is available, and compares those disclosures with findings coming from their own security tools. When a gap remains, teams can request a formal vendor position and track the response through remediation.

The CRA promises greater transparency between software manufacturers and their customers. Tacit makes that transparency operational, turning vendor communication into continuous, actionable oversight of the software you depend on.