A guide to CRA Article 14 reporting requirements
Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting their products.
What has to be reported
A published CVE, a high CVSS score, a high EPSS score (FIRST's exploit-probability score), a KEV entry (CISA's catalogue of known-exploited vulnerabilities), a flaw your own team found: none is a trigger on its own. They are inputs to your assessment. The SRP itself accepts a CVE or an EUVD identifier, the EUVD being ENISA's vulnerability database under NIS2 Art. 12(2).
Exploitation you already knew about. Guidance §217: if you knew of the exploitation before 11 September 2026, no late report is needed for it. That only covers exploitation that had already finished. If it was still happening on or after 11 September, report it. And a vulnerability you knew about with no sign of exploitation becomes reportable the moment exploitation appears.
Legacy products are in scope. Article 69(2) exempts products placed on the market before 11 December 2027 from most CRA requirements, but Article 69(3) pulls Article 14 reporting back into scope for those same products, whether or not they have been modified. Per guidance §210, the reporting duty continues even after the support period ends, though the Annex I Part II vulnerability handling requirements stop once support does.
The three deadlines
The 24- and 72-hour clocks run in parallel from the same moment of awareness, not one after the other. Awareness arrives, per Commission guidance, once an initial assessment gives you reasonable certainty, not when a report lands in your inbox and not when forensics finish.
| Stage | Deadline | What you have to say |
|---|---|---|
| Early warning | 24 hours |
|
| Notification | 72 hours |
|
| Final report | 14 days / 1 month |
|
Who has to report
The manufacturer. Authorised representatives, importers and distributors must inform the manufacturer without undue delay, and market surveillance authorities where the risk is significant (Arts. 19(5), 20(4)), but they do not file. Three situations bend that:
- Rebranding or substantial modification (Art. 21). An importer or distributor selling under its own name or trademark, or substantially modifying a product already on the market, is treated as the manufacturer. Most white-label and OEM arrangements land here; Art. 22 catches anyone else who substantially modifies and makes available.
- No EU main establishment (Art. 14(7)). Report to the Member State where your cybersecurity decisions are predominantly taken, or, if that cannot be determined, wherever your EU establishment has the most employees. With no EU establishment at all, a cascade applies: authorised representative with the most products, then importer, then distributor, then most users. Only the destination changes.
- Open-source stewards (Art. 24(3)). Art. 14(1) applies only where the steward is involved in developing a product; 14(3) and (8) only where an incident hits the systems it provides for that development.
Using the Single Reporting Platform
You file once and the SRP routes it to ENISA and to your coordinating CSIRT, the national team designated as coordinator for the Member State of your main establishment, which passes it onward. Invoke an Art. 16(2) condition at 72 hours and ENISA sees only partial information until the CSIRT releases it. The platform went live on 11 September.
Registering
Pick the AR role, choose your CSIRT, sign in through EU Login, add your manufacturer details. You are then AR Primary User and can invite a backup by email; the invitation expires after seven days. AR here is the SRP's Assigned Representative, an account role, not the Art. 18 authorised representative.
Filing
One case record carries all three stages as tabs, from Draft to Early Warning to 72h Submitted to FR Submitted, after which it locks. Your CSIRT then passes it to other Member States by hand, and may delay that under Art. 16(2) and Del. Reg. (EU) 2026/881. Neither affects your own deadlines.
Three things to know before you file
- Drafts are visible only to whoever created them. Plan the overnight handover around that.
- There is no API. Submission is manual, so automate everything up to the browser and no further.
- CSIRT validation of your AR association runs in parallel with reporting, so a pending validation is never an excuse for a missed deadline.
What to have ready
- EU Login tested for two or three people across time zones.
- Coordinating CSIRT recorded in writing with your Art. 14(7) reasoning. ENISA published the coordinator list on 4 September.
- A named primary and backup AR, and a written rule for who declares awareness, drafts, approves and submits out of hours, with a handover that covers private drafts.
- An internal template mapped to the SRP's mandatory fields, and a product inventory mapped to Member States, including out-of-support items.
- A current SBOM per shipped image, built from the image, not the build manifest.
- A way to test CVE reachability in hours. Helpdesk: cra-srp-helpdesk@enisa.europa.eu



