Article 17 wraps up the CRA's reporting chapter. It lets ENISA share notification information with EU-CyCLONe for large-scale incident coordination, empowers the coordinating CSIRT to inform the public about a severe incident (or require the manufacturer to do so), provides that notifying does not by itself increase the notifier's liability, has ENISA add fixed, publicly known vulnerabilities to the European vulnerability database, gives manufacturers, especially SMEs, helpdesk support from the coordinating CSIRTs, and sets up ENISA's 24-month technical report on emerging cybersecurity risk trends.
Where Article 17 Sits in the Reporting Chapter
The final text of the CRA organises reporting across four articles:
- Article 14: the manufacturer's obligation to report actively exploited vulnerabilities and severe incidents to the coordinating CSIRT and ENISA on the 24-hour, 72-hour, and 14-day (or one-month) timelines, and to inform impacted users under Article 14(8).
- Article 15: voluntary reporting of vulnerabilities, incidents, near misses, and cyber threats by manufacturers and third parties.
- Article 16: the single reporting platform (SRP) that ENISA establishes and the national electronic notification end-points on it.
- Article 17: the provisions around those notifications, covering onward information sharing, public disclosure, liability, the European vulnerability database, and helpdesk support.
If you are looking for the user-notification duty that older commentary sometimes filed under Article 17, in the final Regulation (EU) 2024/2847 it lives in Article 14(8).
Information Sharing with EU-CyCLONe
ENISA may submit information notified under Article 14(1) and (3) and Article 15(1) and (2) to EU-CyCLONe, the European cyber crisis liaison organisation network established under the NIS 2 Directive, where that information is relevant to the coordinated management of large-scale cybersecurity incidents and crises at an operational level. In judging relevance, ENISA may draw on technical analyses performed by the CSIRTs network.
For manufacturers this changes nothing about what you file or when, but it is worth understanding the audience: a severe-incident notification can feed the EU's operational crisis picture, which is one reason the early-warning content should be accurate even when it is brief.
Public Disclosure by the Coordinating CSIRT
Where public awareness is necessary to prevent or mitigate a severe incident having an impact on the security of the product, or to handle an ongoing incident, or where disclosure is otherwise in the public interest, the CSIRT designated as coordinator of the relevant Member State may, after consulting the manufacturer concerned and, where appropriate, in cooperation with ENISA, inform the public about the incident or require the manufacturer to do so.
Practical consequences:
- An incident you notify under Article 14 can become public on the authority's initiative, on a timeline you do not fully control.
- The consultation step is your opportunity to align disclosure with the availability of a fix, so keep remediation status current in every stage of the notification.
- Prepare a public advisory draft alongside the authority notification rather than after it, so a required disclosure does not catch you without user-facing language.
ENISA's 24-Month Trend Report
On the basis of the notifications it receives under Articles 14 and 15, ENISA prepares a technical report on emerging trends regarding cybersecurity risks in products with digital elements every 24 months and submits it to the Cooperation Group established under the NIS 2 Directive, with the first report due within 24 months of the Article 14 obligations applying. Relevant findings also feed ENISA's report on the state of cybersecurity in the Union.
Aggregated notification data therefore has a policy afterlife: it shapes future guidance and enforcement focus, which is another reason accurate classification of your reports matters beyond the individual filing.
No Increased Liability for Notifying
The mere act of notifying in accordance with Article 14(1) and (3) or Article 15(1) and (2) does not subject the notifying natural or legal person to increased liability.
This is the CRA's answer to the classic in-house objection that filing a report creates legal exposure. The notification itself cannot be held against you. Liability, if any, attaches to the underlying non-compliance, not to the act of reporting it, so the shield removes the incentive to sit on a report while the 24-hour clock runs.
The European Vulnerability Database Entry
After a security update or another corrective or mitigating measure is available, ENISA adds a publicly known vulnerability notified under Article 14(1) or Article 15(1) to the European vulnerability database (EUVD) established under the NIS 2 Directive, in agreement with the manufacturer concerned.
Plan for this in your disclosure timeline: once your fix ships, the vulnerability can gain a formal EU-level record. Your public advisory, CVE assignment, and EUVD entry should tell one consistent story about affected versions and remediation.
Helpdesk Support from the Coordinating CSIRTs
The CSIRTs designated as coordinators provide helpdesk support in relation to the Article 14 reporting obligations to manufacturers, and in particular to manufacturers that qualify as microenterprises or as small or medium-sized enterprises.
If you are an SME facing your first 24-hour early warning, your national coordinating CSIRT is a resource you are entitled to use, not only the authority you report to. Identify your designated CSIRT before an incident so the first contact is not made under deadline pressure.
CVD Portal helps you comply with Article 17 automatically.
Public submission portal, 48-hour acknowledgment tracking, Article 14 deadline alerts, and CSAF advisory generation. Receiving and tracking reports is free for all manufacturers placing products with digital elements on the EU market. Article 14 filing with the SRP-ready package is on Pro.
Start your free portalFrequently asked
Does Article 17 add reporting deadlines on top of Article 14?+
No. Article 17 adds no new manufacturer deadlines. Your reporting clocks all come from Article 14: 24 hours for the early warning, 72 hours for the full notification, and 14 days (vulnerabilities) or one month (incidents) for the final report. Article 17 governs what happens with and around those notifications.
Can the authorities publish details of my incident before my fix ships?+
Under Article 17(2) the coordinating CSIRT can inform the public, or require you to, where public awareness is necessary to prevent or mitigate a severe incident, to handle an ongoing incident, or where disclosure is otherwise in the public interest. It must consult you first, which is where remediation timing gets weighed, but the decision is ultimately the authority's. Keep the remediation status in your notifications current so that consultation starts from accurate facts.
Does filing an Article 14 report increase my legal exposure?+
Article 17(4) states that the mere act of notification under Article 14(1) and (3) or Article 15(1) and (2) does not subject the notifier to increased liability. The report itself is shielded. Any liability attaches to the underlying facts, not to your disclosure of them.
Where did the user-notification obligation go?+
In the final Regulation (EU) 2024/2847 the duty to inform impacted users about an actively exploited vulnerability or severe incident, including risk mitigations and, where appropriate, corrective measures, is Article 14(8). Earlier drafts and commentary sometimes grouped it with the surrounding reporting provisions, which is why some older guides file it under a different article number.
Need a CVD policy that satisfies Article 17?
Download a free CRA-compliant template and deploy it in minutes.