compliance-ownerP0Updated
Was this page helpful?

If a Tier A alert has appeared in your workspace, this page is what it means and what to do next. If your alerts list is still empty, that's a correct outcome too — see Quickstart.

Where alerts come from

Every component in your SBOM with a purl is matched against five advisory feeds: NVD, OSV, GHSA, KEV, and EPSS. A match is classified into one of three tiers:

  • Tier A — in the KEV (Known Exploited Vulnerabilities) catalogue, or an EPSS exploitation-probability score at or above the Tier A threshold. This is the only tier that raises an alert and notifies you.
  • Tier B — a meaningful CVSS severity combined with a moderate EPSS score. Shown in your inventory and the weekly digest; no alert.
  • Tier C — recorded in your inventory with no current exploitation signal. No alert, no digest entry.

Tier A/B/C is Declara's own classification, not a CVSS severity rating and not a regulatory term — see the CRA terms glossary for where Declara's vocabulary and the regulation's part ways.

Steps: opening the alert

  1. Open the alert from your Alerts list.
  2. Read what it's telling you. A Tier A alert means a component you ship appears in an exploitation catalogue or has a high exploitation probability. It is a reason to assess — it is not, by itself, a reportable event, and no legal clock has started yet.
  3. Answer the four triage questions:
    • Is the vulnerable component actually used in the shipped product, not only as a development or test dependency?
    • Is the vulnerable code path reachable, or the affected feature enabled, in our product?
    • Do we have any evidence of exploitation against our product or our users?
    • Is a fix or mitigation already available in a shipped version?
  4. Save your answers. A case can't be opened from an alert until all four are answered — this is enforced by the product, not just a form suggestion.

What you should see

Once triage is complete, a case opens. If your answers indicate this is genuinely an actively exploited vulnerability or a severe incident affecting your product, the reporting clock is now relevant — go to File an initial Article 14 report.

If triage concludes the alert doesn't apply to you — the component isn't actually shipped, the path isn't reachable — you can close it out without opening a reporting case. The judgment is yours; Declara's tiering surfaces the signal, not the verdict.