cra-kit: correct Art. 14 reporting mechanics and Art. 18 (an AR is optional); remove ROADMAP.md - #603
cra-kit: correct Art. 14 reporting mechanics and Art. 18 (an AR is optional); remove ROADMAP.md#603sameehj wants to merge 3 commits into
Conversation
e811cee to
84026d1
Compare
Fix a systematic inaccuracy across the kit: Art. 14 reports are not sent "to ENISA" directly. They are filed via the ENISA Single Reporting Platform (SRP) to the CSIRT designated as coordinator, with ENISA notified simultaneously (Art. 14/16), and fixed vulnerabilities are published to the EUVD. - vulnerability-handling-process.md: add "how a report is filed" (SRP -> CSIRT + ENISA -> EUVD) section; add the severe-incident track (Art. 14(3), 1-month final report); reframe on-call from a staffing gap to follow-the-sun coverage plus a compliance commitment; update diagram, SLA table, and references. - Link the EU Authorised Representative appointment to the coordinator-CSIRT reporting end-point (Art. 14(7)) in eu-authorised-representative.md. - Correct "notify ENISA" / "24h ENISA reporting" wording in the shortlist, cheat sheet, glossary, slide outline, and SKILL.md. - Add SRP / CSIRT / EUVD glossary entries; tighten support-period wording to match Art. 13(2) (at least 5 years unless shorter expected lifetime). - Remove internal-correspondence detail from conformity-assessment-route.md. - Delete ROADMAP.md and remove all remaining references to it. Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>
84026d1 to
07efe62
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #603
No scan targets match the changed files in this PR. Review skipped.
Direction is right and I've landed it. The SRP/CSIRT correction is worth having Citations corrected. These were the substantive ones:
Two things that would have misled a reader. Art. 14(7) isn't a single AR rule. With no EU main establishment it's an ordered More important, ENISA's guidance says coordinator-CSIRT validation runs in One place the correction overshot. Art. 14(1) requires notification Nits: canonical SRP URL (yours 301-redirects), and the Added: Art. 69(3) and Art. 71(2) to the references. Worth having explicitly, What I pulled back out, and why. The status flip to a committed Art. 13/14 statement, and the on-call rewrite, are One specific thing to fix before that lands: the PR asserted that the Related and worth a follow-up regardless: §4 of that same live policy still says Separately, a decision that lands on your AR bullet: we're not appointing an |
MarkAtwood
left a comment
There was a problem hiding this comment.
Mechanics corrections are right and verified against the OJ text. Fixes pushed to the branch; status change deferred to its own PR as noted above.
3a073d8 to
07efe62
Compare
MarkAtwood
left a comment
There was a problem hiding this comment.
Sorry for the mess on your branch, that was my doing and you were right to call it. I have reset the branch back to your commit, so this is yours again and you can merge it once these are in.
The SRP/CSIRT direction is right and worth landing before Art. 14 applies on 11 September. Findings below are mostly one-click suggestions. The two that matter are the CVD policy claim and three article cites.
Numbers verified against the OJ text of Regulation (EU) 2024/2847 and the latest consolidated 2019/1020.
Downgrading to comments. None of these block the merge; the citation corrections and the CVD-policy wording will land in a follow-up PR so this can go out for the webinar. Suggestions remain inline for reference.
MarkAtwood
left a comment
There was a problem hiding this comment.
Approving to unblock the webinar. The SRP/CSIRT correction is the right direction and is a clear improvement on what is on master.
Inline suggestions above are not blockers and stay for reference. I will land them in a follow-up PR of my own rather than touching this branch: three article citations (EUVD is 17(5) not 16(2), severe-incident deadlines are 14(4)(c) not 14(3), support period is 13(8) not 13(2)), the Art. 14(7) four-step cascade, the SRP validation wording, and the ASCII box alignment.
One to carry into whatever PR re-raises the status change: the published CVD policy still commits only to acknowledging "as they come in", with no hour targets, so the sentence claiming the 24h/72h targets are reflected there needs the numbers published first or the claim dropped.
|
Merging with an admin override, and that is on me. I pushed commits to this branch earlier, which I should not have done on someone else's PR, then pushed again to reset it back to @sameehj's commit. Branch protection requires the last push to be approved by someone other than the pusher, so my own approval does not count and this cannot merge normally. Sorry for the churn. Rather than make Sameeh push again to work around my mistake, I am overriding. CI is green across all 200+ jobs and the commit is entirely his. The citation corrections and the CVD-policy wording are deferred to a follow-up PR of mine. They are not blockers and this should not wait on them. |
Review fixes for wolfSSL#603. Corrects the citations the previous commit got wrong, and takes the public compliance commitments back out so they can land as their own PR with sign-off. Citations: - ENISA is a co-addressee by statute, not a copy recipient. Art. 14(1) requires notification simultaneously to the coordinator CSIRT and to ENISA; Art. 14(7) directs the submission to the CSIRT end-point, "simultaneously accessible to ENISA". Drop the "not sent to ENISA directly" framing, which overcorrected. - Art. 14(7) sets a four-step cascade where there is no EU main establishment (authorised representative, importer, distributor, Member State with the most users), not a single AR rule. - EUVD publication is Art. 17(5), not Art. 16(2), and carries the "in agreement with the manufacturer" qualifier. The EUVD itself is established under NIS2 Art. 12(2). Corrected in the process doc, the glossary and the references list. - Severe-incident deadlines are in Art. 14(4), with the one-month final report at 14(4)(c). Art. 14(3) is the duty to notify. - Support period is Art. 13(8); Art. 13(2) is the risk-assessment duty. - SRP user validation runs in parallel with reporting and is not a prerequisite for fulfilling the reporting obligation, so it cannot gate a filing. ENISA's "Assigned Representative" is a platform user role, not the Art. 18 authorised representative. - Triage box content line was one column wider than its border. Commitments deferred: - Restore the vulnerability-handling status to the pending-approval state, in the document and in 00-INDEX.md. - Restore the on-call section. The published CVD policy carries no 24h acknowledgement and no 72h triage target, so the packet cannot cite it as the public source for either. Also corrects the remaining "24h ENISA" wording in the 00-INDEX.md timeline, which the previous commit missed. Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com> Co-authored-by: Cursor <cursoragent@cursor.com>
|
Thanks Mark — all eight suggestions applied in 9a26efb, plus the scope change you asked for. Applied as suggested
Scope, per your line-3 comment Four changes beyond your suggestions — please check these
Left alone, needs its own PR
|
Review fixes for wolfSSL#603. Corrects the citations the previous commit got wrong, and takes the public compliance commitments back out so they can land as their own PR with sign-off. Citations: - ENISA is a co-addressee by statute, not a copy recipient. Art. 14(1) requires notification simultaneously to the coordinator CSIRT and to ENISA; Art. 14(7) directs the submission to the CSIRT end-point, "simultaneously accessible to ENISA". Drop the "not sent to ENISA directly" framing, which overcorrected. - Art. 14(7) sets a four-step cascade where there is no EU main establishment (authorised representative, importer, distributor, Member State with the most users), not a single AR rule. - EUVD publication is Art. 17(5), not Art. 16(2), and carries the "in agreement with the manufacturer" qualifier. The EUVD itself is established under NIS2 Art. 12(2). Corrected in the process doc, the glossary and the references list. - Severe-incident deadlines are in Art. 14(4), with the one-month final report at 14(4)(c). Art. 14(3) is the duty to notify. - Support period is Art. 13(8); Art. 13(2) is the risk-assessment duty. - SRP user validation runs in parallel with reporting and is not a prerequisite for fulfilling the reporting obligation, so it cannot gate a filing. ENISA's "Assigned Representative" is a platform user role, not the Art. 18 authorised representative. - Triage box content line was one column wider than its border. Commitments deferred: - Restore the vulnerability-handling status to the pending-approval state, in the document and in 00-INDEX.md. - Restore the on-call section. The published CVD policy carries no 24h acknowledgement and no 72h triage target, so the packet cannot cite it as the public source for either. Also corrects the remaining "24h ENISA" wording in the 00-INDEX.md timeline, which the previous commit missed. Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>
9a26efb to
7668535
Compare
MarkAtwood
left a comment
There was a problem hiding this comment.
Approved.
Verified all four of your beyond-suggestion changes against the diff: the Art. 16 / Art. 17(5) references split, the 00-INDEX timeline wording, the glossary CSIRT row using the Art. 14(7) cascade, and the non-identical on-call revert. Agreed on the last one, a byte-identical revert would have reintroduced the '24h ENISA clock' wording this PR exists to remove. Good catch.
Scope revert is clean: vulnerability-handling-process.md stays 🟡, on-call stays 🟠, 00-INDEX matches. validate-auditor-packet and the rest of CI are green, 200/200.
Two notes, neither blocking:
-
This PR deletes cra-kit/ROADMAP.md (44 lines). The title reads as cleanup of references to an already-deleted file, but the deletion happens here. Flagging so it is on the record rather than a surprise later.
-
Agreed the Art. 18 AR item is out of scope for this PR. Worth prioritising the follow-up though: 00-INDEX.md still shows 'In progress, appointment underway' while we have decided not to appoint one, so the auditor packet currently states an appointment that is not happening. That should not sit in front of an auditor for long.
|
Thanks Mark. Both notes taken, and the second one turned out to be bigger than either of us thought. ROADMAP. You are right, the title read backwards. Retitled to Art. 18. Agreed it should not sit in front of an auditor, and while scoping the follow-up I found a straight legal error underneath the status contradiction. Art. 18(1) reads: "A manufacturer may, by a written mandate, appoint an authorised representative." It is permissive. There is no obligation to appoint one, including for a manufacturer established outside the Union. I checked the usual escape hatch too: Art. 66 CRA only adds the CRA to Annex I of Regulation (EU) 2019/1020, which is the market-surveillance list. It does not bring the CRA under Art. 4 of that Regulation, so there is no back-door requirement for an EU-established economic operator either. The kit currently states the opposite in two places:
The second is worse, because it is customer-facing advice about a duty that does not exist. So the follow-up will do three things rather than one:
Nothing else in the kit needs to move. The glossary CSIRT entry and the new Merging this one now. |
Art. 18(1) reads "a manufacturer may, by a written mandate, appoint an authorised representative". The kit stated the opposite in eight places, telling readers that a manufacturer established outside the EU is obliged to appoint one. That is wrong, and in the customer-facing pages it is advice about a duty that does not exist. Art. 66 CRA adds the CRA only to Annex I of Regulation (EU) 2019/1020, the market-surveillance list. It does not bring products with digital elements under Art. 4 of that Regulation, so there is no indirect requirement for an EU-established economic operator either. Rewrite eu-authorised-representative.md around the correct mechanism: what Art. 18(3) puts in a mandate, what Art. 18(2) keeps with the manufacturer, and how an AR fixes the Art. 14(7) coordinator CSIRT at step 1 of the cascade instead of leaving it to an importer, a distributor, or the Member State with the most users. Also drop the appointment status, the target dates, the third-party vendor shortlist, and the placeholder identity block. The packet no longer asserts that an appointment is underway, and does not assert the opposite either. 00-INDEX.md is updated to match. Follow-up to wolfSSL#603, where this was raised in review as out of scope.
|
@MarkAtwood heads-up: I pushed What changed since you approved. One commit, 11 files. Nothing in the Art. 14 / SRP / EUVD work moved. You flagged that
Permissive. No duty to appoint one, including from outside the Union. I checked the indirect route too, since that is where this normally bites: Art. 66 CRA adds the CRA only to Annex I of Regulation (EU) 2019/1020, the market-surveillance list. It does not bring products with digital elements under Art. 4 of that Regulation, so there is no back-door requirement for an EU-established economic operator. Worth noting which way the error cut. The three things the commit does:
Two things to look at specifically:
|
MarkAtwood
left a comment
There was a problem hiding this comment.
Approved. Checked 18(1), 18(2), 18(3), Art. 66 and Annex V point 2 against the OJ
text, all correct. No counsel needed for the reading, the "may" is on the face of it.
Four for later, none blocking:
- Art. 14 isn't in the 18(2) list (that's 13(1) to (11), 13(12) first subpara, 13(14)).
A mandate can cover the filing; only the duty can't move. Worth splitting that sentence. - Shortlist line 98 still calls the EU AR appointment "in flight", now the last place
in the kit saying we're appointing one. Same for "EU AR status" in Shortlist 95,
README 18, SKILL 26 and 39. - The page is generic now. It belongs in cra-kit/ next to the glossary rather than in
the company packet. - 00-INDEX: every row has a status glyph except this one.
Right call folding this in instead of deferring it.
Summary
Follow-up to #574. Corrects two things the CRA kit stated incorrectly — how an Art. 14 report is filed, and whether an Art. 18 authorised representative is mandatory — and removes
cra-kit/ROADMAP.md.1. Art. 14 reporting mechanic
The kit described reports as going "to ENISA" directly. Under Art. 14/16 a manufacturer files via the ENISA Single Reporting Platform (SRP) to the CSIRT designated as coordinator, with ENISA notified simultaneously; fixed vulnerabilities are then published to the EUVD (Art. 17(5)). Corrected across the shortlist, cheat sheet, glossary, slide outline, and
SKILL.md.vulnerability-handling-process.md: adds a "how an Art. 14 report is filed (SRP → CSIRT + ENISA → EUVD)" section; adds the severe-incident track (Art. 14(3)–(4), one-month final report); updates the diagram, the reporting rows of the service-level table, and the references. No status or commitment change: the headline stays 🟡 and the on-call section stays 🟠.SRP/CSIRT/EUVDentries; the CSIRT entry spells out the full Art. 14(7) cascade (AR, then importer, then distributor, then the Member State with the most users).2. Art. 18 — an authorised representative is optional
This is a legal-position correction and deserves the closest review. Art. 18(1) reads:
It is permissive. There is no duty to appoint one, including for a manufacturer established outside the Union. The kit stated the opposite in eight places, and in the customer-facing pages that was advice about an obligation that does not exist.
The indirect route does not apply either: Art. 66 CRA adds the CRA only to Annex I of Regulation (EU) 2019/1020, which is the market-surveillance list. It does not bring products with digital elements under Art. 4 of that Regulation, so there is no back-door requirement for an EU-established economic operator.
eu-authorised-representative.mdrewritten around the correct mechanism: what Art. 18(3) puts in a mandate, what Art. 18(2) keeps with the manufacturer (Art. 13(1)–(11), (12) first subpara, (14) cannot be delegated), and how an AR fixes the Art. 14(7) coordinator CSIRT at step 1 of the cascade instead of leaving it to an importer, a distributor, or the Member State with the most users. The trade-off is now presented as a decision for the reader's own counsel.README.md,SKILL.md(twice),auditor-packet/00-INDEX.md, the DoC template, and the technical-documentation outline.🟠 In progress — appointment underwayrow inwolfssl-inc-auditor-packet/00-INDEX.md. The packet no longer asserts that an appointment is underway, and does not assert the opposite either.3. ROADMAP
Removes
cra-kit/ROADMAP.md(44 lines) and all remaining links and text references to it. The deletion happens in this PR. Its practical content is not lost:CRA_LICENSE_OVERRIDE,SOURCE_DATE_EPOCH,pkg:githubandmake bomshare all covered inREADME.md, the glossary, the cheat sheet, andSKILL.md.Also:
conformity-assessment-route.mddrops internal-correspondence detail from a customer-facing template.Test plan
cra-kit/scripts/validate.shpasses (auditor packet validation OK)cbom-draft.cdx.jsonstill parses as valid JSONROADMAPreferences incra-kit/00-INDEX.mdstatus matchesvulnerability-handling-process.md