ntop and the EU Cyber Resilience Act

Under the EU Cyber Resilience Act (CRA), it has become compulsory for manufacturers of products sold on the EU market to report exploited vulnerabilities and severe incidents. As a result, ntop is fully committed to compliance with these new requirements. Since September 11, 2026, Article 14 of the CRA requires ntop to report security issues directly to the ENISA Single Reporting Platform (SRP). When a report is submitted here, it is simultaneously routed to both ENISA and the relevant national Computer Security Incident Response Team (CSIRT).

We are required to report two specific types of events:

  • Actively Exploited Vulnerabilities: Any flaw in ntop software where we have reliable evidence that a malicious actor is currently exploiting it in the wild.
  • Severe Incidents: Any security event that seriously compromises the availability, authenticity, integrity, or confidentiality of ntop software.

For many years, ntop has been committed to secure coding, always doing our best to keep our products safe and bug-free. We perform continuous code testing using AI-based automated processes, code fuzzing, and manual code reviews. However, we are aware that security incidents can happen. Therefore, we invite you to contact us to report security issues or ask anything related to cybersecurity and ntop’s CRA obligations.

Below you can find useful references on this subject:

Thank you very much for your help and support.

Share