“CRA notification” -> What does it mean? A CRA notification is an actively exploited vulnerability affecting one of its products is discovered. There is no fixed term “CRA notification” in the regulation defined. The CRA talks about notifications and reports. So if ADLINK wants to use this term to point out the connection to the CRA we need to define this maybe in the notification or report template? “CRA report” -> What does it mean? Same as with term “CRA notification”. Not defined by regulation itself, but we can use it as defined by our own. Which obligations are owned by ADLINK EMEA, which parts are delegated to ADLINK TPE? That is part of the upcoming discussion resulting finally in a SOP. Document ATGD_CRA_regulation_line_of_reasoning.docx lists the reporting obligations in chapter 3.6 starting on 11-Sep-2026 and future obligations in chapter 3.7 starting on 11-Dec-2027. The SOP shall document the tasks for ATG and ADTW finally. „regulatory, contractual, and internal requirements“ -> Which REFs do we need to include in this document? Depending on discussion and distributed tasks. Who owns and legally represent this document? Author, Approval, Owner by law for the EMEA ADLINK entity (GM = Marco Krause?). Has to be discussed with QM Angelika? Comprehensive overview of all internal and external stakeholders. -> Breakdown needed. OK, define while discussing the SOP Obligation are changing: Before and after 11DEC2027? No, obligations are already defined in the CRA and are mandatorily to be followed starting on two different dates, see above How does the product scope of delivery is impacting the process? Have no idea, discuss and define, if required in the SOP Systems vs components. For different verticals? If required… For simple application and use, we recommend not to differentiate between both. We have to discuss if this results in a SOP, a process document, or both.