CRA Article 14 is a reporting obligation — not a vulnerability-handling checklist. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents that affect the security of products with digital elements through ENISA’s Single Reporting Platform (SRP).
If you opened this page looking for SBOM, triage, or mergeable fixes: that is Annex I Part II (vulnerability handling), which largely applies from 11 December 2027. We cover that in a separate post. This URL stays on Article 14 — the three clocks that already started.
What does CRA Article 14 require?
Article 14 requires manufacturers to notify actively exploited vulnerabilities and severe incidents that impact the security of a product with digital elements. You file once via the CRA Single Reporting Platform, addressed to the CSIRT of your main establishment, with the information also made available to ENISA except in narrow exceptional cases. See the Commission’s reporting page.
The three clocks (24 / 72 / final)
Use this as the operating grid. Times run from when you become aware.
Early warning — within 24 hours
Submit an early warning without undue delay and in any event within 24 hours of becoming aware. This is the “something is actively wrong / being exploited” signal — not a finished RCA.
Full notification — within 72 hours
Within 72 hours, submit the fuller notification with the information then available (nature of the exploit/vulnerability or incident, product context, and early mitigations for users where known).
Final report
For actively exploited vulnerabilities: final report no later than 14 days after a corrective measure is available. For severe incidents: final report within one month from the 72-hour notification. Confirm details on the Commission reporting page and ENISA SRP guidance when you train the on-call path.
Worked timeline (Sunday 02:00 awareness)
Imagine the pager fires Sunday 02:00 local: credible evidence your product is under active exploitation.
- By Monday 02:00 — early warning filed in the SRP (24h).
- By Tuesday 02:00 — full 72-hour notification filed with what you know then.
- When a corrective measure ships — start the 14-day final-report clock for an actively exploited vulnerability (or follow the severe-incident final-report rule).
If your “awareness” process is informal Slack archaeology, you do not have an Article 14 process. You have hope.
What does “becoming aware” mean in practice?
Regulators will not accept “we saw the CVE tweet three weeks later” as a strategy. Operationalize awareness:
- Named intake for exploit intel (vendor advisories, customers, researchers, SOC, bug bounty)
- On-call owner who can open an SRP draft at 02:00 — credentials, legal contact, product inventory
- Written rule for when a finding becomes “actively exploited” or a “severe incident” for CRA purposes (with counsel)
- Log of when awareness started — that timestamp owns the clocks
Where do you file — CSIRT and the Single Reporting Platform?
Manufacturers report once through ENISA’s Single Reporting Platform. The notification goes to the CSIRT designated for the Member State of main establishment; information is shared onward to other relevant CSIRTs where the product is made available, unless exceptional delay rules apply. Bookmark the Commission page and ENISA SRP docs before the next incident — not during it.
Article 14 vs Annex I Part II (do not conflate)
Article 14 = reporting clocks + SRP/CSIRT path for actively exploited vulnerabilities and severe incidents (in force for manufacturers from 11 September 2026).
Annex I Part II = vulnerability handling as an essential cybersecurity requirement (intake, SBOM/inventory, triage, remediation, disclosure) — mainly from 11 December 2027 with the broader CRA obligations (Commission CRA overview).
An SBOM does not satisfy Article 14. An SBOM may support Annex I handling evidence. Different jobs.
FAQ
What does CRA Article 14 require?
It requires manufacturers to report actively exploited vulnerabilities and severe security incidents for products with digital elements: early warning within 24 hours of awareness, fuller notification within 72 hours, and a final report on the timelines above — filed via ENISA’s Single Reporting Platform to the relevant CSIRT.
When did CRA Article 14 reporting start?
For manufacturers, reporting obligations apply from 11 September 2026. Open-source software steward reporting under Article 24(3) follows later (11 December 2027 per Commission CRA reporting guidance). Always re-check the Commission page for your role.
Does an SBOM alone satisfy Article 14?
No. Article 14 is about timely reporting of actively exploited vulnerabilities and severe incidents through the SRP. SBOMs belong to vulnerability-handling / inventory evidence under Annex I Part II — not a substitute for the 24/72/final reporting path.
Is Article 14 only for “cybersecurity products”?
No. The CRA targets products with digital elements on the EU market. Scope and product class still need legal review — but AppSec and product security usually own the awareness and filing muscle.
What to do this week
- Confirm who can log into the SRP and which CSIRT is yours
- Write the Sunday-02:00 runbook: awareness timestamp → 24h → 72h → final
- Separate the Annex I handling backlog (SBOM, triage, mergeable fixes) so it does not get mislabeled as Article 14
Talk to us if you want a dry-run of reporting readiness alongside intent-preserving remediation for the handling side.
Sources: Commission — CRA reporting obligations; ENISA — Single Reporting Platform launch; Commission — Cyber Resilience Act overview.
