In partnership with ECI Ireland

Cyber Vulnerability Reporting: Fundamentals

Prepare for EU Cyber Resilience Act vulnerability reporting

From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe security incidents under the EU Cyber Resilience Act (CRA). An early warning is due within 24 hours and a fuller notification within 72 hours.

Reporting to authorities is only part of the picture. The same people also handle researcher reports, coordinated vulnerability disclosure (CVD), bug bounty submissions and supplier notifications, and each of these carries its own expectations around evidence, timing and confidentiality.

Short deadlines leave little room to work out who is responsible, what evidence is required and how information should be escalated. This practical course helps you put those foundations in place.

Delivered in partnership by ECI Ireland and Comply.Land.

Course specification

Delivery
Online and self-paced
Duration
Approximately 4 hours
Availability
From 9 September 2026, start at any time
Access period
40 calendar days from activation
Language
English
Level
Foundation
Assessment
Scenario assessment, 70% pass mark
Certificate
Certificate of Achievement issued by ECI
CPD hours
Yes*
Training partnership
ECI Ireland and Comply.Land
Course author
Daniel Thompson-Yvetot
Individual fee
€325

Intended participants

This course is for people involved in developing, manufacturing, importing or distributing software, connected devices and other products with digital elements in the European Union.

It is particularly relevant to business leaders and professionals working in information technology, security, software development, quality assurance, product management, compliance, risk, legal or technical support.

Technical and non-technical participants are welcome. Advanced cybersecurity experience is not required.

Learning outcomes

After completing the course, you will be able to:

  • Differentiate private disclosure, coordinated vulnerability disclosure, public disclosure, bug bounty reporting and incident reporting
  • Meet the vulnerability reporting and process requirements of the CRA
  • Follow the reporting and coordinated-disclosure lifecycle from discovery to public disclosure
  • Identify the people responsible for assessment and escalation
  • Recognise common reporting failures
  • Apply ethical and legally aware handling principles
  • Identify gaps in your organisation's current process

Practical course outputs

You will produce five foundation artefacts:

  1. Stakeholder map
  2. Current-state reporting process map
  3. Vulnerability lifecycle diagram
  4. Capability gap analysis
  5. Initial maturity assessment

These practical outputs help clarify responsibilities, reveal weak handovers and establish a baseline for improvement. They are documents you keep and use after the course ends.

Course structure

Part 1 · 60 minutes

Foundation lesson

Terminology, disclosure models, stakeholder roles and CRA context.

Part 2 · 60 minutes

Practical deep dive

Disclosure in practice, common failure points and a guided scenario.

Part 3 · 60 minutes

Artefact workshop

Guided development of the five foundation artefacts.

Part 4 · 60 minutes

Scenario assessment

A structured response to a supplied report and evidence set.

A glossary explains the principal cybersecurity, vulnerability-disclosure and CRA terminology used throughout this fully online, self-paced course.

Assessment and recognition

The course concludes with a practical scenario in which you apply the vulnerability-reporting process to a supplied report and evidence set.

Your response is evaluated on correct classification, stakeholder identification, escalation, missing evidence, ethical and legally aware handling and the quality of the practical artefacts produced.

The pass mark is 70%. Learners who do not reach it may retake the assessment, up to three attempts in total. Learners who pass receive a Certificate of Achievement issued by ECI and co-branded with Comply.Land, which can be downloaded on completion.

*The course is suitable for continuing professional development and you can submit it to your professional body for CPD hours. The number of hours awarded is decided by that body, so we cannot guarantee a specific figure.

Enrolment and access

Enrolment and payment are handled by ECI. Access details are issued within 48 hours of payment.

Access runs for 40 calendar days from activation. Each learner receives a named account, which is not transferable.

The course is self-paced, so you do not need to complete it in one sitting and you can return to the material as often as you like during the access period. Set aside around four hours for the taught content, plus additional time to complete the five artefacts for your own organisation.

Your course author

This course was written by Daniel Thompson-Yvetot, chief executive officer of CrabNebula, founder of Comply.Land and a European Telecommunications Standards Institute (ETSI) Rapporteur working on the technical standards underpinning the Cyber Resilience Act.

The course is delivered in partnership by ECI Ireland and Comply.Land.

The lessons are narrated by a synthetic voice generated from Daniel Thompson-Yvetot's own voice, with his consent. All course content, assessment criteria and learner feedback remain under human authorship and oversight.

Establish the process before a report arrives

Build the knowledge and practical foundations your organisation needs to handle vulnerability reports with greater clarity and confidence.