Cyber Resilience Act
Near miss
Legal definition Art. 3(45) CRA
“a near miss as defined in Article 6, point (5), of Directive (EU) 2022/2555”
A near miss under the Cyber Resilience Act (CRA) is an event that could have compromised the security of data or services but was prevented from materialising, or never materialised in the first place. Article 3, point (45) does not define the term itself; it refers to Article 6, point (5), of Directive (EU) 2022/2555, the NIS2 Directive.
The wording there: an event that could have compromised the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data, or of the services offered by or accessible via network and information systems, but that was successfully prevented from materialising or that did not materialise.
One word separates it from an incident
The definition of an incident in Article 6, point (6), of the same directive is word for word identical except for the outcome. There the event is one “compromising” those properties; here it is one that “could have compromised … but that was successfully prevented from materialising”. Same four protected properties, same categories of data, same range of services.
Classification therefore turns on whether something happened, not on how bad it was. An attack that got past a control and then altered data is an incident, however slight the damage. An attack that failed at network separation is a near miss, however large it would have grown.
Not reportable
Article 14 knows two reporting triggers: the actively exploited vulnerability and the severe incident having an impact on the security of the product. Near misses appear in neither. No 24-hour clock runs for them, no 72-hour notification, no final report.
That is not an oversight but the deliberate boundary of the reporting obligations: what gets reported is what actually happened.
The voluntary route under Article 15
Article 15(2) opens a second channel. Manufacturers, and expressly other natural or legal persons as well, may notify any incident having an impact on the security of the product, as well as near misses that could have resulted in such an incident, to a CSIRT designated as coordinator or to ENISA on a voluntary basis.
Two details are worth noting. First, the voluntary channel is wider than the mandatory one: it does not require the underlying incident to have been severe. Second, it runs over the same single reporting platform established under Article 16, although CSIRTs are free to prioritise mandatory notifications over voluntary ones.
On timing, Article 15 applies only from the regulation’s full application date of 11 December 2027. Under Article 71(2) the only provisions brought forward are Article 14, applying from 11 September 2026, and Chapter IV (Articles 35 to 51) on the notification of conformity assessment bodies, applying from 11 June 2026.
Where such a notification goes
A voluntary near-miss notification does not travel far beyond the CSIRT. Article 16(3) obliges CSIRTs to make notified information available to their market surveillance authority only for actively exploited vulnerabilities and severe incidents; near misses are not listed there.
The main use is statistical. From the notifications under Articles 14 and 15, ENISA produces a technical report every 24 months on emerging cybersecurity risk trends in products with digital elements. Where the information matters for managing large-scale crises, it may additionally be passed to the EU-CyCLONe network.
What the CRA leaves open
The regulation contains no duty to record or evaluate near misses internally. Neither Article 13 nor Annex I mentions them. Keeping a register is a matter of self-interest.
The technical precondition for one, however, is required: Annex I, Part I, point (2)(l) obliges products (on the basis of the Article 13(2) risk assessment and where applicable) to provide security related information by recording and monitoring relevant internal activity, including the access to or modification of data, services or functions, with an opt-out mechanism for the user. Without those logs a prevented attack is simply invisible. And the question of whether an incident occurred or not cannot then be answered within 24 hours when it counts.
Practical questions
-
No, because treating it that way would drain the category of meaning. Port scans, failed logins and blocked off-the-shelf exploits are the background noise of any reachable system. A near miss requires that a realistic path to compromise existed and that a specific safeguard cut it off, as when an attacker actually reaches a vulnerable component but is stopped by network separation. Without a written threshold you end up with either an empty register or an unusably full one.
-
Not necessarily. Article 15(4) obliges the CSIRT to inform the manufacturer without undue delay only where a third party notifies an actively exploited vulnerability or a severe incident. Near misses are not in that list. So do not count on the official route. Your own reporting channel for security researchers, customers and operators remains the more dependable source.
-
The regulation guards against that explicitly. Article 15(5) provides that voluntary reporting must not impose obligations that would not have applied without the notification, and CSIRTs designated as coordinators and ENISA must keep the information confidential and appropriately protected. Article 17(4) adds that the mere act of notifying does not create increased liability. What remains untouched is the prevention, investigation, detection and prosecution of criminal offences: a notification does not cure unlawful conduct.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.