Tech

Sep 18, 2026

 · 

6

 min read

CRA Article 14: Vulnerability & Incident Reporting Guide

Cyber Resilience Act CRA Article 14 Guide
A guide to CRA Article 14 reporting requirements
September 2026

A guide to CRA Article 14 reporting requirements

Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting their products.

Why this matters: Article 14 was the first CRA obligation to reach manufacturers, 15 months ahead of CE marking. Annex I Part II handling, Art. 13(6) upstream reporting and Art. 15 voluntary reporting all wait until 11 December 2027 (Art. 71(2)).

What has to be reported

An actively exploited vulnerability in your product Vulnerabilities where there's reliable evidence that a malicious actor has exploited it in a system, without the owner's permission (Art. 3(42)).
A severe incident affecting your product's security Incidents that meet either of the two Art. 14(5) conditions; one is enough. Either the incident harms, or could harm, the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions; or it has led, or could lead, to malicious code being introduced into or run on the product or a user's system.

A published CVE, a high CVSS score, a high EPSS score (FIRST's exploit-probability score), a KEV entry (CISA's catalogue of known-exploited vulnerabilities), a flaw your own team found: none is a trigger on its own. They are inputs to your assessment. The SRP itself accepts a CVE or an EUVD identifier, the EUVD being ENISA's vulnerability database under NIS2 Art. 12(2).

Exploitation you already knew about. Guidance §217: if you knew of the exploitation before 11 September 2026, no late report is needed for it. That only covers exploitation that had already finished. If it was still happening on or after 11 September, report it. And a vulnerability you knew about with no sign of exploitation becomes reportable the moment exploitation appears.

Legacy products are in scope. Article 69(2) exempts products placed on the market before 11 December 2027 from most CRA requirements, but Article 69(3) pulls Article 14 reporting back into scope for those same products, whether or not they have been modified. Per guidance §210, the reporting duty continues even after the support period ends, though the Annex I Part II vulnerability handling requirements stop once support does.

The three deadlines

The 24- and 72-hour clocks run in parallel from the same moment of awareness, not one after the other. Awareness arrives, per Commission guidance, once an initial assessment gives you reasonable certainty, not when a report lands in your inbox and not when forensics finish.

StageDeadlineWhat you have to say
Early warning24 hours
  • Who you are, which product, a one-line title.
  • For an incident: whether you suspect deliberate malicious action.
  • Which Member States the product is sold in, if you know.
A flag, not a report. You are not expected to know much yet.
Notification72 hours
  • What the vulnerability or incident actually is, and how it is being exploited.
  • For an incident, your initial assessment of it.
  • What you have done about it, and what users should do.
  • How sensitive you consider the information to be.
Final report14 days / 1 month
  • The full account: severity, impact, root cause, and the fix. This is the only stage where severity and impact are mandatory.
  • Vulnerabilities: 14 days after a fix or mitigation exists.
  • Incidents: one month after the 72-hour notification.
Three things people miss. The 14-day clock starts when a fix exists, not at awareness. Under Art. 14(6) your CSIRT can request an intermediate report in between. Art. 14(8) separately requires you to inform impacted users, and where appropriate all users, which the Commission treats as risk-based rather than a duty to publish. And Art. 64(10)(a) removes the fine for micro and small enterprises that miss the 24-hour warning, not the obligation, and not for medium-sized enterprises.

Who has to report

The manufacturer. Authorised representatives, importers and distributors must inform the manufacturer without undue delay, and market surveillance authorities where the risk is significant (Arts. 19(5), 20(4)), but they do not file. Three situations bend that:

  • Rebranding or substantial modification (Art. 21). An importer or distributor selling under its own name or trademark, or substantially modifying a product already on the market, is treated as the manufacturer. Most white-label and OEM arrangements land here; Art. 22 catches anyone else who substantially modifies and makes available.
  • No EU main establishment (Art. 14(7)). Report to the Member State where your cybersecurity decisions are predominantly taken, or, if that cannot be determined, wherever your EU establishment has the most employees. With no EU establishment at all, a cascade applies: authorised representative with the most products, then importer, then distributor, then most users. Only the destination changes.
  • Open-source stewards (Art. 24(3)). Art. 14(1) applies only where the steward is involved in developing a product; 14(3) and (8) only where an incident hits the systems it provides for that development.
Third-party components are still yours to report. Guidance §218: if a vulnerability in a component you ship is being exploited in your product, you notify it, whoever wrote the code. If the vulnerable code is unreachable, meaning it cannot be reached or executed in your build, or has not been exploited there, no report is due, but record that determination. The supplier reports only where the component is itself a commercial product with digital elements.

Using the Single Reporting Platform

You file once and the SRP routes it to ENISA and to your coordinating CSIRT, the national team designated as coordinator for the Member State of your main establishment, which passes it onward. Invoke an Art. 16(2) condition at 72 hours and ENISA sees only partial information until the CSIRT releases it. The platform went live on 11 September.

Registering

Pick the AR role, choose your CSIRT, sign in through EU Login, add your manufacturer details. You are then AR Primary User and can invite a backup by email; the invitation expires after seven days. AR here is the SRP's Assigned Representative, an account role, not the Art. 18 authorised representative.

Filing

One case record carries all three stages as tabs, from Draft to Early Warning to 72h Submitted to FR Submitted, after which it locks. Your CSIRT then passes it to other Member States by hand, and may delay that under Art. 16(2) and Del. Reg. (EU) 2026/881. Neither affects your own deadlines.

Three things to know before you file

  • Drafts are visible only to whoever created them. Plan the overnight handover around that.
  • There is no API. Submission is manual, so automate everything up to the browser and no further.
  • CSIRT validation of your AR association runs in parallel with reporting, so a pending validation is never an excuse for a missed deadline.

What to have ready

Do not pre-register. ENISA advises registering “only when they need to submit a specific notification, rather than creating an account pre-emptively.” The goal is being able to register and submit within 24 hours under pressure. Prepare now:
  • EU Login tested for two or three people across time zones.
  • Coordinating CSIRT recorded in writing with your Art. 14(7) reasoning. ENISA published the coordinator list on 4 September.
  • A named primary and backup AR, and a written rule for who declares awareness, drafts, approves and submits out of hours, with a handover that covers private drafts.
  • An internal template mapped to the SRP's mandatory fields, and a product inventory mapped to Member States, including out-of-support items.
  • A current SBOM per shipped image, built from the image, not the build manifest.
  • A way to test CVE reachability in hours. Helpdesk: cra-srp-helpdesk@enisa.europa.eu
Sources: Regulation (EU) 2024/2847 (CRA), Arts. 3(42), 13, 14, 16, 18 to 22, 24(3), 64(10)(a), 69(2) and (3), 71(2) · Del. Reg. (EU) 2026/881 · Commission guidance C(2026) 5252, §9.1, §§209 to 221 · Commission, CRA reporting · ENISA CRA SRP FAQ and AR guidance pages, August 2026
Article and paragraph numbers are cited throughout so every statement can be checked. This is intended to be informative, not legal advice.
Share this resource
By subscribing, you agree to Exein’s Privacy Policy.
Thank you for your interest.
Download
Your download will begin automatically. If it doesn’t,

click here to download it manually.
Oops! Something went wrong while submitting the form.
Subscribe to our newsletter
By subscribing, you agree to Exein’s Privacy Policy.
You’re subscribed
We’ll keep you updated with the latest from Exein.
Oops! Something went wrong while submitting the form.

Built by you, trusted by your customers, secured by Exein

No items found.
No items found.
No items found.