CRA Product Security Pack
The CRA Product Security Pack covers Stella Ops’ own manufacturer/supplier-facing product-security posture: vulnerability intake, support lifecycle records, product advisory publication, and public metadata preflight. This page is for the Stella Ops product-security team; it sits under the CRA Assurance Packs index.
Claim boundary: manufacturer-self.
Primary evidence scope: stella-product. The same release, SBOM/VEX, support lifecycle, CVD, advisory, and incident-notification facts can be packaged as stella-supplier evidence for operators that deploy Stella.
Source Docs
- Stella Product CSAF Advisory Contract v1
- Stella Supplier Evidence Profile v1
- Product CSAF Notify channel
- Assurance Setup Prerequisites v1
- CRA gap-closure research
- EU compliance decisions log
- Stella supplier-security statement
Runtime Boundary
This pack is for vulnerabilities in Stella itself. Customer product-security contacts, advisory feeds, and release-support promises are separate tenant or customer-product configuration and must not reuse Stella manufacturer claims.
Live publication remains blocked until public routes, security mailbox delivery, access validation, and a non-expired encryption-capable intake key are verified. Those checks should not block local technical-file or conformity-dossier export.
Product Copy
Use “Stella product-security publication” or “manufacturer publication preflight.” Do not use “CRA compliant mode.”
Article 14 Reporting Profile
Runtime profile id: cra.article14.incident.
Notify exposes this profile at GET /api/v1/assurance/reporting-timeline-profiles/cra.article14.incident. Persisted timeline records remain on GET /api/v1/regulatory/reporting-timelines?regime=cra.
The CRA Article 14 countdown starts from the recorded classification event (cra.incident.classified) and uses the shared Notify reporting timeline: 24-hour early warning, 72-hour vulnerability notification, and 14-day final report. The profile’s manufacturer-self claim boundary is valid for Stella-as-manufacturer reporting only.
For customer products, Stella may provide timeline control, signed evidence, and handoff packets, but the customer manufacturer remains the reporting party. Do not put Stella’s manufacturer identity into customer-product reporter fields, and do not use this pack to imply that Stella auto-files with ENISA or another authority on the customer’s behalf.
Change Log
| Date (UTC) | Update |
|---|---|
| 2026-06-16 | Reconciled to verified code: the 24h/72h/14d Article 14 timeline state machine, the cra.incident.classified countdown anchor, the signed envelope builder, and the operator-filesystem handoff are shipped and tested (src/Notify/StellaOps.Notify.WebService/Services/IncidentReportTimelineService.cs, src/Notify/__Libraries/StellaOps.Notify.Connectors.Enisa/); security.txt + CSAF feed are served by the Gateway product-metadata provider. The ENISA SRP auto-submit HTTP transport remains a stub (default = operator filesystem handoff) and SRP schema validation is pinned blocked until an official schema is vendored — auto-submit stays explicit opt-in and is never live regulator receipt. See cra-gap-closure-plan.md §Remaining CRA gaps G2/G4. |
