← CRA Guide
Article 14

Active Exploitation and Incident Reporting - 24h, 72h, and 14-Day Obligations

Article 14 of the EU Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities and severe incidents to ENISA and their coordinator CSIRT from 11 September 2026, with an early warning within 24 hours, a full notification within 72 hours, and a final report within 14 days. It is the first CRA obligation to apply, fifteen months ahead of the rest of the regulation.

Effective: September 2026Applies to: All manufacturers of products with digital elements sold in the EU marketLast reviewed: 27 July 2026Verified against: the final text of Regulation (EU) 2024/2847
Source: Regulation (EU) 2024/2847, Article 14, official text on EUR-Lex

What are the three Article 14 reporting deadlines?

Article 14 establishes a three-stage notification process triggered by active exploitation of a vulnerability or a severe security incident:

StageDeadlineWhat to Report
Early Warning24 hoursNotification that exploitation is occurring; basic product and vulnerability information
Vulnerability Notification72 hoursFull notification including CVSS score, affected versions, initial mitigations
Final Report14 days after a fix is available (vulnerability), or one month after the 72-hour notification (incident)Complete analysis, root cause, patch or workaround, supply chain impact

The first two deadlines are calculated from the moment the manufacturer becomes aware of the active exploitation or incident - not from when exploitation began. The final report runs on a different clock, and this is the detail most summaries get wrong. For an actively exploited vulnerability, Article 14(2)(c) gives you 14 days from the moment a corrective or mitigating measure is available, not from awareness. For a severe incident, Article 14(4)(c) gives you one month from the submission of the 72-hour incident notification. The full legal text is set out in Article 14 of Regulation (EU) 2024/2847 on EUR-Lex.

CRA reference:Article 14(1)–(3)

When does a manufacturer 'become aware'?

Every Article 14 deadline runs from the moment the manufacturer becomes aware, and the Regulation does not define that moment. Commission guidance C(2026) 5252 does. On detecting a suspicious event, or on a third party such as a researcher, customer, authority or media organisation bringing something to its attention, the manufacturer should assess it immediately. Awareness arises when, after that initial assessment, there is a reasonable degree of certainty that a vulnerability contained in the product is being actively exploited, or that a severe incident has occurred and has compromised the security of the product.

Receiving a report therefore does not by itself start the clock, and neither does an unexamined suspicion. A short triage window sits in front of the 24 hours. It is not open-ended, and the guidance stresses prompt action to carry out the initial assessment, particularly where the vulnerability may pose a significant risk.

The Commission deliberately aligned this reading with recital 31 of Implementing Regulation (EU) 2024/2690 under NIS2 and with Section II(A) of the EDPB guidelines on personal data breach notification under the GDPR, so that a manufacturer subject to several regimes can apply one awareness standard. The guidance is non-binding, and only the Court of Justice of the European Union can give an authoritative interpretation.

CRA reference:Article 14(1) and (3); Commission guidance C(2026) 5252 points 211 to 215

What triggers Article 14 reporting?

Two conditions trigger Article 14 notification:

  1. Active exploitation - A vulnerability in your product is being actively exploited in the wild. This means there is evidence of real-world attacks using the vulnerability, not just proof-of-concept code.
  1. Severe security incident - A security incident that has (or may have) a significant impact on the security of users of your product, or a significant impact on the internal operations of your organisation.

Not triggered by: Theoretical vulnerabilities, vulnerabilities with no known exploitation, low-severity bugs, or normal vulnerability reports received through your CVD programme that are not actively exploited.

CRA reference:Article 14(1)

Where do you submit an Article 14 report?

Notifications must be submitted to the CSIRT designated as coordinator in the member state where you have your main establishment, and to ENISA. Each EU member state designates a coordinator CSIRT for this purpose.

ENISA is establishing a Single Reporting Platform for Article 14 notifications. Until this is operational, manufacturers should contact their national CSIRT directly.

CVD Portal can draft Article 14 notifications in the required format and alert you when deadlines are approaching.

CRA reference:Article 14(1), Article 14(7)

The 24-Hour Early Warning

The 24-hour early warning is not a full technical report - it is a rapid notification that exploitation is occurring. ENISA uses this signal to coordinate cross-border incident response before the full picture is known.

  • Product name and affected version(s)
  • Nature of the vulnerability or incident (brief description)
  • Indication that active exploitation is occurring
  • Geographic scope if known
  • Initial mitigation actions taken (if any)

You do not need to have a root cause analysis or patch ready at this stage. Speed of notification is the priority.

CRA reference:Article 14(2)(a)

The 72-Hour Full Notification

Within 72 hours of becoming aware of active exploitation, you must submit a full vulnerability notification. This expands on the early warning with:

  • CVSS 3.1 (or 4.0) score and vector string
  • CVE identifier (or a request for one if not yet assigned)
  • Affected products, versions, and configurations
  • Description of the impact on confidentiality, integrity, and availability
  • Known attack vectors and exploitation techniques
  • Mitigations available (patches, workarounds, configuration changes)
  • Supply chain impact assessment (are other products affected?)

72 hours is a very tight window for a complete analysis. This means your incident response process must be able to move very quickly when an active exploitation is confirmed.

CRA reference:Article 14(2)(b)

The 14-Day Final Report

The final report closes the case with ENISA and the coordinating CSIRT. Its deadline depends on which trigger you are reporting. For an actively exploited vulnerability, Article 14(2)(c) gives you 14 days from the moment a corrective or mitigating measure is available. For a severe incident, Article 14(4)(c) gives you one month from the submission of the 72-hour incident notification. It must include:

  • Root cause analysis
  • Complete remediation details (patch release, advisory publication)
  • CSAF advisory (if applicable)
  • Supply chain coordination actions taken
  • Steps taken to prevent recurrence
  • Lessons learned

If the case is still open when your clock runs out, submit what you have and explain what remains under investigation. Separately, under Article 14(6) the coordinating CSIRT that received your notification can request an intermediate report on status updates at any point between the stages.

CRA reference:Article 14(2)(c)

What are the Article 14 supply chain obligations?

Article 14 has significant supply chain implications. If a vulnerability affects components you source from third-party vendors, you are still responsible for the Article 14 notification for your product - but you must also:

  1. Notify the component vendor if the vulnerability originates in their component
  2. Coordinate with them on remediation timelines
  3. Report the supply chain dimension in your Article 14 notifications

Conversely, if you are a component supplier and your component is found to be vulnerable, you must notify downstream manufacturers who integrate your component. This creates a notification cascade up and down the supply chain.

CRA reference:Article 14(4)

Does the obligation apply retroactively or after support ends?

No to the first and yes to the second. Commission guidance C(2026) 5252 confirms that Article 14 applies from 11 September 2026 to all products with digital elements in scope, including products placed on the market before 11 December 2027, and that the reporting obligations continue after a product is no longer supported. Vulnerability handling under Annex I Part II behaves differently and stops with the support period.

There is no retroactive reporting. A manufacturer is not required to report active exploitation it had already become aware of before 11 September 2026. Where a vulnerability was known before that date but its active exploitation was not, either because none had occurred or because the manufacturer had not learned of it, and exploitation occurs or comes to light after that date, the vulnerability is reportable.

A vulnerability originating in an integrated third-party component is reportable only where it is actively exploited in your product. Where the vulnerable code is unreachable, or exploitation has not occurred in your product, no mandatory report arises. Voluntary notification under Article 15 remains available, the Annex I Part II handling requirements still apply, and Article 13(6) still requires the vulnerability to be reported upstream to whoever maintains the component.

CRA reference:Articles 14, 15 and 69(3); Commission guidance C(2026) 5252 points 210, 217 and 218

CVD Portal helps you comply with Article 14 automatically.

Public submission portal, 48-hour acknowledgment tracking, Article 14 deadline alerts, and CSAF advisory generation. Receiving and tracking reports is free for all manufacturers placing products with digital elements on the EU market. Article 14 filing with the SRP-ready package is on Pro.

Start your free portal

Frequently asked

Does Article 14 apply to every vulnerability I discover?+

No. Article 14 only applies when there is active exploitation of a vulnerability in your product or a severe security incident. Vulnerabilities discovered through your CVD programme that are not being actively exploited are handled under Article 13, not Article 14.

What if I can't complete the 72-hour report on time?+

The regulation requires reasonable effort. If a full technical analysis is not possible within 72 hours, submit what you have and note that the report is preliminary. ENISA would rather receive an incomplete but timely notification than a complete report submitted late. Document your reasons for any delay.

How do I know if exploitation is 'active'?+

Active exploitation means there is credible evidence that attackers are using the vulnerability in real attacks. This includes: reports from customers of successful attacks, detection by threat intelligence services, exploitation code seen in the wild, or confirmation from a national CSIRT. A publicly available PoC without confirmed exploitation does not automatically trigger Article 14, but the risk level increases significantly.

Does Article 14 apply to vulnerabilities found by internal security testing?+

No. Article 14 is triggered by active exploitation or severe incidents, not by internally discovered vulnerabilities. Internal vulnerability management is covered under Article 13 (product security requirements) and Article 13 (CVD policy). Article 14 is specifically about responding to real-world attacks.

What is the penalty for missing an Article 14 deadline?+

Missing Article 14 notification deadlines can result in fines up to €15 million or 2.5% of global annual turnover. More immediately, failure to notify can result in product recall orders and increased scrutiny from national market surveillance authorities.

Need a CVD policy that satisfies Article 14?

Download a free CRA-compliant template and deploy it in minutes.

Browse templates →