Cyber Resilience Act
CRA Article 14: what to report, to whom and how fast
Article 14 of the Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities and severe incidents in their products from 11 September 2026: an early warning within 24 hours of becoming aware, a notification within 72 hours and a final report later, sent to the coordinating CSIRT and ENISA through the single reporting platform.
Free plan, no card required.
What triggers a report?
Two situations start the clock. The first is an actively exploited vulnerability: the Regulation defines it as a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without the owner's permission. A vulnerability that merely exists in your product, or has a high score, is not enough on its own.
The second is a severe incident having an impact on the security of the product. Article 14(5) calls an incident severe when it affects, or can affect, the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or when it has led or can lead to malicious code being introduced into the product or the users' systems.
The deadlines, stage by stage
The windows run from the moment the manufacturer becomes aware, not from the moment a fix is ready. That is why the first report asks for so little: it is a warning, not an analysis.
| Stage | Actively exploited vulnerability | Severe incident |
|---|---|---|
| Early warning | Within 24 hours of becoming aware, including the Member States where the product is available | Within 24 hours, including whether unlawful or malicious acts are suspected |
| Notification | Within 72 hours: general information, corrective or mitigating measures, how sensitive the information is | Within 72 hours: nature of the incident, initial assessment, measures taken |
| Final report | No later than 14 days after a corrective or mitigating measure is available | Within one month after the incident notification |
Who receives the reports?
Every notification goes simultaneously to the CSIRT designated as coordinator and to ENISA, through the single reporting platform that ENISA runs under Article 16. The competent CSIRT is the one of the Member State where the manufacturer has its main establishment in the Union; a manufacturer without one follows a fallback order that starts with its authorised representative. The coordinating CSIRT may ask for an intermediate report on the status of the situation.
ENISA announced the initial operating capability of the platform on 11 September 2026, the day Article 14 started to apply. Manufacturers also have to inform the users affected, and where appropriate all users, about the vulnerability or incident and any measures they can take, where appropriate in a structured, machine-readable format.
Does Article 14 cover products already on the market?
Yes. Most of the Regulation only applies to products placed on the market from 11 December 2027, but Article 69(3) makes an exception for reporting: Article 14 applies to all in-scope products, including those placed on the market before that date. The Commission's FAQ confirms that for such products the manufacturer must report, while the other obligations, such as vulnerability handling, do not apply to them.
How to be ready before the 24 hours start
Twenty-four hours is not enough time to find out what a product contains. The work that makes the deadline realistic happens beforehand.
- Keep an up-to-date SBOM for every product version still on the market, not only for the main branch.
- Watch known-exploited sources such as the CISA KEV catalogue and ENISA's EU Vulnerability Database for your components.
- Name the person who decides whether a vulnerability is actively exploited in your product, and a deputy.
- Register with the single reporting platform and know which CSIRT is your coordinator.
- Prepare report templates so the early warning can be filled in minutes.
- Record every decision and the evidence behind it; the final report will need it.
Penalties and the small-company exemption
Breaching Article 14 falls in the highest band of Article 64: up to €15 million or 2.5% of worldwide annual turnover, whichever is higher. Micro and small enterprises cannot be fined for missing the 24-hour early-warning deadline, but the obligation to report still applies to them.
Available in KROMSE today
KROMSE prepares the reports; a person decides, completes, approves and submits them.
- On paid plans, internal drafts for all six Article 14 stages (early warning, notification and final report, for vulnerabilities and for incidents), as PDF.
- Fields KROMSE cannot know are left blank for a person to fill in, never guessed.
- Findings flagged when the CISA KEV catalogue lists the vulnerability as known exploited, with EPSS, NVD and ENISA EUVD context.
- CRA response cases with the 24-hour and 72-hour deadlines and recorded human decisions.
- SBOMs for every scan, so you know which products contain an affected component.
Coming next
On the roadmap, not available yet. Dates are targets, not promises; this page changes the day a capability is live.
- Coming · Q1 2027Submission to ENISA's single reporting platform. After a person approves an Article 14 report, KROMSE will send it to ENISA's single reporting platform.
- Coming · Q4 2026 (December)Monitoring on your schedule, with AI agents. Rescans will run on a schedule you set, with AI agents that watch for new advisories, triage what applies, propose fixes and draft the report for your review.
Frequently asked questions
When does CRA Article 14 apply?
From 11 September 2026. From that date manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of their products, including products placed on the EU market before the rest of the Regulation applies in December 2027.
What is the ENISA single reporting platform?
It is the system ENISA set up under Article 16 of the Cyber Resilience Act to receive Article 14 notifications. A report submitted there reaches the CSIRT designated as coordinator and ENISA at the same time. ENISA announced its initial operating capability on 11 September 2026.
Does a critical CVE in my product have to be reported?
Not by itself. Article 14 is about actively exploited vulnerabilities, meaning there is reliable evidence that a malicious actor has exploited it without the system owner's permission. A severity score alone does not trigger a report, although the vulnerability still has to be handled.
What goes into the 24-hour early warning?
The early warning is short by design. For an actively exploited vulnerability it includes, where applicable, the Member States where the product has been made available. For a severe incident it states whether the incident is suspected of being caused by unlawful or malicious acts.
Can KROMSE submit reports to ENISA for me?
Not today. KROMSE drafts the reports and keeps the evidence, and a person in your organisation approves and submits them. Sending an approved report to the single reporting platform from inside KROMSE is on the roadmap.