In partnership with ECI Ireland
Cyber Vulnerability Reporting: Fundamentals
Prepare for EU Cyber Resilience Act vulnerability reporting
From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe security incidents under the EU Cyber Resilience Act (CRA). An early warning is due within 24 hours and a fuller notification within 72 hours.
Reporting to authorities is only part of the picture. The same people also handle researcher reports, coordinated vulnerability disclosure (CVD), bug bounty submissions and supplier notifications, and each of these carries its own expectations around evidence, timing and confidentiality.
Short deadlines leave little room to work out who is responsible, what evidence is required and how information should be escalated. This practical course helps you put those foundations in place.
Delivered in partnership by ECI Ireland and Comply.Land.
Course specification
- Delivery
- Online and self-paced
- Duration
- Approximately 4 hours
- Availability
- From 9 September 2026, start at any time
- Access period
- 40 calendar days from activation
- Language
- English
- Level
- Foundation
- Assessment
- Scenario assessment, 70% pass mark
- Certificate
- Certificate of Achievement issued by ECI
- CPD hours
- Yes*
- Training partnership
- ECI Ireland and Comply.Land
- Course author
- Daniel Thompson-Yvetot
- Individual fee
- €325
Intended participants
This course is for people involved in developing, manufacturing, importing or distributing software, connected devices and other products with digital elements in the European Union.
It is particularly relevant to business leaders and professionals working in information technology, security, software development, quality assurance, product management, compliance, risk, legal or technical support.
Technical and non-technical participants are welcome. Advanced cybersecurity experience is not required.
Learning outcomes
After completing the course, you will be able to:
- Differentiate private disclosure, coordinated vulnerability disclosure, public disclosure, bug bounty reporting and incident reporting
- Meet the vulnerability reporting and process requirements of the CRA
- Follow the reporting and coordinated-disclosure lifecycle from discovery to public disclosure
- Identify the people responsible for assessment and escalation
- Recognise common reporting failures
- Apply ethical and legally aware handling principles
- Identify gaps in your organisation's current process
Practical course outputs
You will produce five foundation artefacts:
- Stakeholder map
- Current-state reporting process map
- Vulnerability lifecycle diagram
- Capability gap analysis
- Initial maturity assessment
These practical outputs help clarify responsibilities, reveal weak handovers and establish a baseline for improvement. They are documents you keep and use after the course ends.
Course structure
Foundation lesson
Terminology, disclosure models, stakeholder roles and CRA context.
Practical deep dive
Disclosure in practice, common failure points and a guided scenario.
Artefact workshop
Guided development of the five foundation artefacts.
Scenario assessment
A structured response to a supplied report and evidence set.
A glossary explains the principal cybersecurity, vulnerability-disclosure and CRA terminology used throughout this fully online, self-paced course.
Assessment and recognition
The course concludes with a practical scenario in which you apply the vulnerability-reporting process to a supplied report and evidence set.
Your response is evaluated on correct classification, stakeholder identification, escalation, missing evidence, ethical and legally aware handling and the quality of the practical artefacts produced.
The pass mark is 70%. Learners who do not reach it may retake the assessment, up to three attempts in total. Learners who pass receive a Certificate of Achievement issued by ECI and co-branded with Comply.Land, which can be downloaded on completion.
*The course is suitable for continuing professional development and you can submit it to your professional body for CPD hours. The number of hours awarded is decided by that body, so we cannot guarantee a specific figure.
Enrolment and access
Enrolment and payment are handled by ECI. Access details are issued within 48 hours of payment.
Access runs for 40 calendar days from activation. Each learner receives a named account, which is not transferable.
The course is self-paced, so you do not need to complete it in one sitting and you can return to the material as often as you like during the access period. Set aside around four hours for the taught content, plus additional time to complete the five artefacts for your own organisation.
Your course author
This course was written by Daniel Thompson-Yvetot, chief executive officer of CrabNebula, founder of Comply.Land and a European Telecommunications Standards Institute (ETSI) Rapporteur working on the technical standards underpinning the Cyber Resilience Act.
The course is delivered in partnership by ECI Ireland and Comply.Land.
The lessons are narrated by a synthetic voice generated from Daniel Thompson-Yvetot's own voice, with his consent. All course content, assessment criteria and learner feedback remain under human authorship and oversight.
Establish the process before a report arrives
Build the knowledge and practical foundations your organisation needs to handle vulnerability reports with greater clarity and confidence.