How to Report a Vulnerability to Ezurio – Our Compliance Process with the EU Cyber Resilience Act

On September 11, 2026, the EU’s requirements for incident reporting in security software come into effect. All providers of products with cybersecurity elements must establish reporting mechanisms by this date. Here’s how Ezurio is preparing for these requirements, which may serve as a template for customers with their own compliance needs.

By Kurt Furlong

Published on September 9, 2026

A Requirement Across the Board for Risk Management

The EU’s Cyber Resilience Act (CRA) has been in effect since November of 2024, but some of its key elements are still phasing in as part of its complete rollout. The latest is the requirement that manufacturers of connected products must establish mechanisms for customers to report security incidents and vulnerabilities, with the remainder of the CRA’s cybersecurity requirements coming into force by December 11, 2027. 

As a part of our compliance with this legislation, Ezurio has formed a Product Security Incident Response Team (PSIRT) to regularly monitor and audit security risks raised by multiple reporting platforms and those raised by our customers. In this post, we’ll discuss what our PSIRT does, how to report an incident or exposure to Ezurio, and what happens when your issue is entered into our auditing process. 

Our Model for Incident Response

Ezurio builds cybersecurity and resiliency requirements into its hardware and software design controls from the outset. These design processes are part of Ezurio's Quality System and are audited and certified under ISO 9001.

Ezurio’s Product Security Incident Response Team monitors not just the experiences and concerns of our immediate customers, but Single Reporting Platforms (SRPs) such as Mitre (https://www.cve.org/),  CISA (https://www.cisa.gov/) and in particular to the EU ENISA (https://www.enisa.europa.eu/). Part of how we accomplish this is with automated processes tied to the Software Bill-of-Materials (SBOM) for our software products. We check and cross reference the entirety of our software offerings against Known Vulnerabilities and Exposures (KVEs). This allows us to stay ahead of global research and provide the most up-to-date and secure instances of the many software packages we integrate into our own offerings. 

In addition, Ezurio provides a mechanism to report any found vulnerabilities directly to Ezurio for evaluation. Customers can report known vulnerabilities to Ezurio at the following link: https://www.ezurio.com/security/report. When reported, the members of our PSIRT reviews and reports to those vulnerability platforms in compliance with the requirements of the CRA. That means disclosing an early warning within 12 hours, a detailed description within 72 hours, and a detailed report of mitigation after 14 days. 

Not only does Ezurio report to these SRPs, but we’ll post them on our website as well, in the disclosures section of the Our Approach to Security page on Ezurio.com: https://www.ezurio.com/security/our-approach-to-security#disclosures. This allows all customers the ability to monitor these issues in real time, at each of the early warning, detailed description, and mitigation stages. 

The bottom line for customers

If you discover or suspect a vulnerability in an Ezurio product, we ask you to report it here: https://www.ezurio.com/security/report. From there, Ezurio's PSIRT takes over: confirming the issue, notifying regulators where required, and keeping you informed through a defined disclosure timeline. That structure is designed to give customers confidence that vulnerabilities are handled quickly and transparently, in step with the EU's new regulatory expectations.

For more on Ezurio’s approach to device security, visit our website: 

www.ezurio.com/security