Article 14 reporting applies from 11 September 2026
Menu
Article 14 reporting applies from 11 September 2026

The CRA reporting clock, stage by stage

An actively exploited vulnerability and a severe incident start the same three-stage clock, and only the last stage runs to different end dates. All of it goes to one place.

Last verified August 19, 2026

From 11 September 2026, Article 14 gives a manufacturer an early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report whose deadline depends on which trigger it was. Everything goes to the ENISA single reporting platform, routed to the coordinator CSIRT of your main establishment.

StageDeadlineActively exploited vulnerabilitySevere incident
Early warningWithin 24 hours of the manufacturer becoming awarean actively exploited vulnerability (Art. 14(2)(a))a severe incident (Art. 14(4)(a))
Full notificationWithin 72 hours of becoming awarevulnerability notification (Art. 14(2)(b))incident notification (Art. 14(4)(b))
Final reportSee each column — the two triggers run to different end datesno later than 14 days after a corrective or mitigating measure is available (Art. 14(2)(c))within one month after submission of the 72-hour incident notification (Art. 14(4)(c))

Whether the clock is running at all

Seven questions decide it, and what it costs when it is.

When Article 14 starts to apply

11 September 2026

Where the report goes

Once, via the single reporting platform established under Article 16 (set up and operated by ENISA), to the electronic notification end-point of the CSIRT designated as coordinator of the member state of the manufacturer's main establishment in the Union — simultaneously accessible to ENISA. Main establishment = where cybersecurity decisions are predominantly taken, falling back to the most EU employees. With no main establishment in the Union, Article 14(7) supplies a FOUR-step order, on the information available to the manufacturer: (a) member state of the authorised representative acting for the most products, (b) of the importer placing the most products on the market, (c) of the distributor making the most products available, (d) the member state in which the highest number of users of the manufacturer's products are located. A manufacturer reporting under point (d) may send notifications of any subsequent actively exploited vulnerability or severe incident to the same coordinator CSIRT it first reported to.

Fine relief for micro and small

Administrative fines are disapplied to manufacturers that qualify as microenterprises or small enterprises with regard to any failure to meet the deadline referred to in Article 14(2)(a) or Article 14(4)(a) — the two 24-hour early warnings, and nothing else

What counts as micro or small

Microenterprise — fewer than 10 staff and annual turnover and/or annual balance sheet total not exceeding €2 million. Small enterprise — fewer than 50 staff and annual turnover and/or annual balance sheet total not exceeding €10 million. Partner and linked enterprises (broadly, a 25%-or-more holding) are pulled into the calculation under Article 3 of the Annex.

The penalty ceiling

€15,000,000 or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher

Anything owed retroactively

No. Because the duty attaches to becoming aware of active exploitation, a manufacturer is not required to report vulnerabilities of whose active exploitation it had already become aware before 11 September 2026; the CRA does not require retroactive reporting. The converse does bind: where the manufacturer knew of a vulnerability before that date but was not aware of any active exploitation, and exploitation occurs or comes to its attention after 11 September 2026, the vulnerability is deemed actively exploited and the reporting duty applies.

A third-party component

No. The duty covers actively exploited vulnerabilities contained in the manufacturer's own product. Where a third-party component carries a vulnerability that either cannot be exploited in the product (the guidance gives unreachable vulnerable code as the example) or has not been exploited in it, that vulnerability is not subject to mandatory reporting by that manufacturer. Voluntary notification under Art. 15 remains available, and the Annex I Part II vulnerability-handling duties and the Art. 13(6) upstream report to the component maintainer still apply.

Every figure above is the value carried in this site’s claim register, re-verified against its primary source on 2026-07-29. Source: Regulation (EU) 2024/2847, Article 14(2)(a) and 14(4)(a).