This is an interesting point of view. I've been thinking that only the moment counts, when the manufacturer has been made aware, regardless when the manufacturer has in fact actively become aware. Thanks!
I have a lot of contact with the CRA at work and I actually think its a very good piece of regulation. There are barely any parts where I think they are straight up bad.
I think it only hurts super small one man part time developers but even then: If I pay for a piece of software I expect it to be secure and have a bit of support.
https://www.enisa.europa.eu/topics/product-security/single-r...
> Reporting process starts at the moment manufacturer becomes aware of active exploitation of vulnerability or incident.
If your business is closed (due to vacation or sickness for example) you don't become aware until you are back.