Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
When must you report under CRA Article 14?
Updated
Article 14 of Regulation (EU) 2024/2847 (CRA) sets a 24-hour early warning, a 72-hour notification, and a 14-day final report on the actively-exploited track. Those three marks are not one number. This page is not legal advice and does not start a clock.
CRA jurisdiction guide, last verified 8 September 2026 against Regulation (EU) 2024/2847 Articles 3, 14, 16, 24, 69(3) and 71(2), ENISA's Single Reporting Platform FAQ (updated 7 September 2026 — agency guidance, not the regulation), and the European Commission's CRA reporting page. It is not legal advice, not a filing, not a determination that CRA applies, and not a substitute for counsel.
This is CRA Article 14, not YOUR product class
Audience: a product, engineering, or compliance lead at an organisation that might be a manufacturer of products with digital elements under Regulation (EU) 2024/2847. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that CRA applies, that you are a manufacturer, that a product with digital elements has been made available on the Union market, that you have become aware, or that you must file.
Article 14 is a legal requirement only if the Cyber Resilience Act applies to YOUR facts. Article 3(13) defines manufacturer as a natural or legal person who develops or manufactures products with digital elements or has them designed, developed or manufactured, and markets them under its name or trademark. This page does not apply that definition to YOU. Last verified 8 September 2026. Not legal advice.
- Statute versus guidance: Articles 14, 16, 69(3) and 71(2) are legal requirements only if they apply. ENISA's Single Reporting Platform materials and the Commission's CRA reporting page and implementation FAQs are guidance, not the regulation. This page quotes which kind of text it is relying on.
- This page does not start 24 hours, does not start 72 hours, and does not start 14 days. Those three marks are not blended into one number. The 14-day mark on the actively-exploited track is not the one-month mark on the severe-incident track.
- The reporting-deadlines page on this site is the statute table of clocks. The reporting-decision-tree page on this site is the branching tree. The NIS2 incident-reporting guide on this site is Article 23 — a different instrument from Article 14. The GDPR breach-notification guide on this site is Articles 33–34.
- The DORA incident-reporting guide on this site is Articles 18–19 — a different instrument from CRA Article 14.
- The signed-in CRA ladder tracks recorded awareness for findings the organisation classified as CRA-in-scope. That tracker does not start an Article 14 clock, does not decide that CRA applies, and does not file with a CSIRT or ENISA. A named human still submits.
Applicability and dates — Article 71(2) and Article 69(3)
Last verified 8 September 2026 against the regulation on EUR-Lex. Article 71(2): this Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026, and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026. Those dates are in the regulation. This page does not move them.
Article 69(3): by way of derogation from Article 69(2), the obligations laid down in Article 14 shall apply to all products with digital elements that fall within the scope of this Regulation that have been placed on the market before 11 December 2027. Article 14 reporting is not delayed until full application in December 2027.
This block is not a determination that YOU are in scope, that a named product is a product with digital elements, or that a clock has started. Counsel applies those tests to YOUR facts.
| What applies | Date in the regulation | Source | Last verified |
|---|---|---|---|
| Article 14 reporting obligations of manufacturers | 11 September 2026 | Article 71(2), second subparagraph. Legal requirement. | 8 September 2026 |
| Chapter IV — notification of conformity assessment bodies (Articles 35 to 51) | 11 June 2026 | Article 71(2), second subparagraph. Not the Article 14 reporting ladder. | 8 September 2026 |
| The rest of the Regulation, including essential cybersecurity requirements | 11 December 2027 | Article 71(2), first subparagraph. | 8 September 2026 |
| Article 14 as applied to products already placed on the market before 11 December 2027 | The Article 14 duties apply to in-scope products placed on the market before that date (derogation from Article 69(2)). | Article 69(3). Legal requirement. This page does not find that YOUR product was placed on the market. | 8 September 2026 |
| Open-source software steward duties in Article 24(3) | Article 71(2) names Article 14 — not Article 24 — as the 11 September 2026 exception. ENISA's SRP FAQ (updated 7 September 2026) states that corresponding steward reporting under Article 24(3) applies from 11 December 2027. That FAQ is agency guidance, not the regulation. | Article 24(3); Article 71(2); ENISA SRP FAQ points 4 and 29 — guidance. | 8 September 2026 |
What you need to do now
As of last verification on 8 September 2026, Article 14 applies from 11 September 2026 — three days from that verification date. The list below is operational preparation. It is not a determination that CRA applies to YOU, that you are a manufacturer, or that a reporting clock has started. Walk it with counsel.
- Ask counsel whether YOU are a manufacturer of a product with digital elements made available on the Union market. This page does not run that test. Marking CRA in an obligation map is not that determination.
- If counsel says Article 14 may apply, identify the CSIRT designated as coordinator under Article 14(7) (main establishment in the Union, or the cascade if you have none). This page does not name YOUR CSIRT.
- Decide how the organisation will record the minute it becomes aware of an actively exploited vulnerability or a severe incident, in UTC. Do not treat reading this page as becoming aware. The signed-in ladder, if you use it, tracks recorded awareness — it does not decide that minute.
- ENISA has published that the Single Reporting Platform is scheduled to be operational from 11 September 2026. As of 8 September 2026 the production filing portal is not yet live. ENISA's SRP FAQ (updated 7 September 2026) names https://portal.cra-srp.enisa.europa.eu and states the portal will be available from 11 September 2026. That URL is ENISA's published address, not a live filing this page can confirm. Do not invent a different portal.
- ENISA's SRP FAQ (guidance, not the regulation) describes Assigned Representatives logging in with EU Login and multi-factor authentication. Registration and CSIRT validation of that association are ENISA/CSIRT process, not Article 14 itself.
- Do not paste NIS2's one-month final report onto CRA's 14-day actively-exploited final report. Do not paste CRA's 14-day mark onto the severe-incident one-month final report. Do not treat a KEV listing as automatic becoming-aware.
Triggers — actively exploited vulnerability versus severe incident
Article 14 has two mandatory tracks. They share a 24-hour early warning and a 72-hour notification. They diverge at the final report. This page does not invent a CVE list, a KEV list, or a severity score that the article does not state. Last verified 8 September 2026. Not legal advice.
- Do not invent a CVE catalogue as the trigger. Article 14(1) is awareness of an actively exploited vulnerability contained in the product, as Article 3(42) defines that term.
- A KEV match, a scanner alert, or a customer report may be how you learn a fact. None of those events is, by itself, the legal finding that you have become aware. Counsel maps YOUR facts.
- Open-source software stewards are a different Article 3(14) class. Article 24(3) applies Article 14(1) to stewards to the extent they are involved in the development of the products, and Article 14(3) and (8) to the extent severe incidents affect network and information systems they provide. This page does not classify YOU as a steward.
| Trigger | What the text says | Kind of text | Last verified |
|---|---|---|---|
| Actively exploited vulnerability — Article 14(1) | A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7, and to ENISA, via the single reporting platform established pursuant to Article 16. | Legal requirement — Article 14(1). Only if CRA applies. | 8 September 2026 |
| Actively exploited vulnerability — definition | Article 3(42): a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner. Article 3(40) defines vulnerability; Article 3(41) defines exploitable vulnerability. Those three definitions are not the same. | Legal requirement — Article 3(40)–(42). This page does not find that YOUR CVE is actively exploited. | 8 September 2026 |
| Severe incident — Article 14(3) | A manufacturer shall notify any severe incident having an impact on the security of the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7, and to ENISA, via the same platform. | Legal requirement — Article 14(3). | 8 September 2026 |
| Severe — Article 14(5) | An incident having an impact on the security of the product with digital elements shall be considered to be severe where: (a) it negatively affects or is capable of negatively affecting the ability of a product with digital elements to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions; or (b) it has led or is capable of leading to the introduction or execution of malicious code in a product with digital elements or in the network and information systems of a user of the product with digital elements. | Legal requirement — Article 14(5). Qualitative. This page does not score YOUR incident. | 8 September 2026 |
| Incident having an impact on the security of the product | Article 3(44): an incident that negatively affects or is capable of negatively affecting the ability of a product with digital elements to protect the availability, authenticity, integrity or confidentiality of data or functions. | Legal requirement — Article 3(44). Distinct from Article 14(5)'s severe test. | 8 September 2026 |
Timeline table — 24-hour, 72-hour, and 14-day as separate rows
The 24-hour early warning, the 72-hour notification, and the 14-day final report are three distinct marks. This page does not average them, does not round 72 hours to three days, and does not treat 14 days as the severe-incident final report. Clock-start is the event the cited point names. Last verified 8 September 2026. Not legal advice. This table does not start a clock.
- Article 14(7): notifications are submitted via the single reporting platform using the electronic notification end-point of the CSIRT designated as coordinator of the Member State where the manufacturers have their main establishment in the Union, and shall be simultaneously accessible to ENISA. Main establishment is where decisions related to the cybersecurity of the products are predominantly taken; if that cannot be determined, the establishment with the highest number of employees in the Union.
- If there is no main establishment in the Union, Article 14(7) third subparagraph sets a cascade: authorised representative, then importer, then distributor, then the Member State in which the highest number of users are located — based on information available to the manufacturer. This page does not run that cascade for YOU.
- The who-to-notify page on this site is the recipient-class map. The how-regulators-determine-knowledge page on this site is the clock-start analysis.
| Stage | Deadline (statutory words) | Clock starts | Recipient | Source | Last verified |
|---|---|---|---|---|---|
| Early warning — actively exploited vulnerability | Without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, an early warning notification, indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available. | The manufacturer becoming aware of the actively exploited vulnerability. Article 14(2)(a). This page does not find that you have become aware, and it does not start the 24 hours. | The CSIRT designated as coordinator and ENISA, via the single reporting platform. Articles 14(1), 14(7) and 16. | Article 14(2)(a). Legal requirement. | 8 September 2026 |
| Vulnerability notification — 72 hours | Unless the relevant information has already been provided, a vulnerability notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the actively exploited vulnerability, with general information as available about the product, the general nature of the exploit and of the vulnerability, corrective or mitigating measures taken, measures users can take, and, where applicable, how sensitive the manufacturer considers the notified information to be. | The manufacturer becoming aware of the actively exploited vulnerability. Article 14(2)(b). Same start event as the 24-hour early warning — not a second, later start. The 24-hour band and the 72-hour band are not averaged into one number. | The CSIRT designated as coordinator and ENISA, via the single reporting platform. | Article 14(2)(b). Legal requirement. | 8 September 2026 |
| Final report — 14 days after a measure is available (actively exploited track) | Unless the relevant information has already been provided, a final report, no later than 14 days after a corrective or mitigating measure is available, including at least: a description of the vulnerability, including its severity and impact; where available, information concerning any malicious actor that has exploited or that is exploiting the vulnerability; and details about the security update or other corrective measures that have been made available to remedy the vulnerability. | Measure availability — not awareness. Article 14(2)(c). The 14-day mark is not the 24-hour mark and not the 72-hour mark. This page does not find that a measure is available. | The CSIRT designated as coordinator and ENISA, via the single reporting platform. | Article 14(2)(c). Legal requirement. | 8 September 2026 |
| Early warning — severe incident | Without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, including at least whether the incident is suspected of being caused by unlawful or malicious acts, and indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product has been made available. | The manufacturer becoming aware of the severe incident. Article 14(4)(a). Not the 14-day mark. | The CSIRT designated as coordinator and ENISA, via the single reporting platform. | Article 14(4)(a). Legal requirement. | 8 September 2026 |
| Incident notification — 72 hours (severe-incident track) | Unless the relevant information has already been provided, an incident notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the incident, with general information where available about the nature of the incident, an initial assessment, corrective or mitigating measures taken, measures users can take, and, where applicable, sensitivity. | The manufacturer becoming aware of the incident. Article 14(4)(b). Same start event as that track's 24-hour early warning. | The CSIRT designated as coordinator and ENISA, via the single reporting platform. | Article 14(4)(b). Legal requirement. | 8 September 2026 |
| Final report — one month after the 72-hour incident notification (severe-incident track) | Unless the relevant information has already been provided, a final report, within one month after the submission of the incident notification under point (b), including at least a detailed description of the incident including its severity and impact, the type of threat or root cause that is likely to have triggered the incident, and applied and ongoing mitigation measures. | Submission of the incident notification under Article 14(4)(b) — not awareness, and not measure availability. This page does not convert 'one month' into a number of hours. This one-month mark is not the 14-day mark on the actively-exploited track. Those two final-report marks are not averaged. | The CSIRT designated as coordinator and ENISA, via the single reporting platform. | Article 14(4)(c). Legal requirement. | 8 September 2026 |
| Intermediate report on request | Where necessary, the CSIRT designated as coordinator initially receiving the notification may request manufacturers to provide an intermediate report on relevant status updates about the actively exploited vulnerability or severe incident. | A request — not becoming aware, and not a fixed hour count in Article 14(6). | The CSIRT designated as coordinator that requested it. | Article 14(6). Legal requirement. | 8 September 2026 |
| Inform impacted users | After becoming aware of an actively exploited vulnerability or a severe incident having an impact on the security of the product with digital elements, the manufacturer shall inform the impacted users of the product, and where appropriate all users, of that vulnerability or incident and, where necessary, of any risk mitigation and corrective measures that the users can deploy, where appropriate in a structured, machine-readable format that is easily automatically processable. | After becoming aware. Article 14(8) does not convert that duty into a 24-hour, 72-hour, or 14-day count. This page does not invent one. | Impacted users, and where appropriate all users. If the manufacturer fails to inform users in a timely manner, the notified CSIRTs designated as coordinators may provide that information when considered proportionate and necessary. | Article 14(8). Legal requirement. Distinct from the CSIRT/ENISA filings. | 8 September 2026 |
Single reporting platform — only what ENISA and the Commission currently publish
Article 16(1): for the notifications referred to in Article 14(1) and (3) and Article 15(1) and (2), a single reporting platform shall be established by ENISA. Day-to-day operations are managed and maintained by ENISA. The architecture shall allow Member States and ENISA to put in place their own electronic notification end-points. That is the legal requirement.
What ENISA and the Commission currently publish, last verified 8 September 2026: ENISA's CRA SRP page and SRP FAQ (FAQ updated 7 September 2026) state that the platform is scheduled to be operational from 11 September 2026, coinciding with Article 14 application. The Commission's CRA reporting page (as fetched) states the same operational-by date and that functional and security testing are under way. ENISA FAQ 28 names https://portal.cra-srp.enisa.europa.eu and states the portal will be available from 11 September 2026.
As of 8 September 2026 this page cannot confirm that the production filing portal is live. ENISA has published that it will be available from 11 September 2026. This page does not invent a live portal, an API, or a national substitute URL. ENISA FAQ 15 (guidance) states that no API will be provided at the initial release. ENISA FAQ 25 (guidance) states that if the SRP is temporarily unavailable, manufacturers should wait until it becomes available again and then submit; contacting the CSIRT directly does not replace the SRP filing once the platform is available.
Article 15 voluntary reporting is a different stream. ENISA FAQ 4 and 27 (guidance) state that voluntary reporting under Article 15 will not be available at launch. That is platform sequencing, not a rewrite of Article 15.
Legal requirement versus Commission and ENISA guidance
The table below labels each text. Do not treat guidance as the article, and do not treat the article as optional because a FAQ exists. Last verified 8 September 2026. Not legal advice.
| Text | What it is | What this page does not do |
|---|---|---|
| Regulation (EU) 2024/2847 Articles 3, 14, 16, 24, 69(3), 71(2) | Legal requirement — the regulation, only if it applies. | Does not apply those articles to YOU. |
| Commission Delegated Regulation (EU) 2026/881 | Delegated act specifying terms and conditions for delaying dissemination of notifications under Article 16(2), adopted 11 December 2025 as Article 14(9) required. Not Article 14 itself. | Does not find that YOUR notification meets a delay ground. |
| European Commission CRA reporting page and Commission FAQs on CRA implementation (section 5) / CRA implementation guidance (section 9.1) | Commission materials. Guidance, not the regulation. | Does not treat a Commission FAQ as a substitute for Article 14. |
| ENISA Single Reporting Platform page, SRP FAQ (updated 7 September 2026), SRP Glossary, SRP factsheet | Agency guidance on the platform ENISA establishes under Article 16. Not the regulation. | Does not treat an ENISA FAQ as starting YOUR clock, and does not treat a named portal URL as proof the production system is live on the verification date. |
How this differs from NIS2 Article 23 and DORA Article 19
Do not paste one ladder onto another. The NIS2 incident-reporting guide on this site is Directive (EU) 2022/2555 Article 23. The DORA incident-reporting guide on this site is Regulation (EU) 2022/2554 Article 19. CRA is Regulation (EU) 2024/2847 Article 14. Last verified 8 September 2026. Not legal advice.
- Filing one does not discharge another. A CRA Article 14 notification is not a NIS2 Article 23 early warning and not a DORA Article 19 initial notification.
- Recital 12 discusses cloud services designed and developed outside the responsibility of a manufacturer, and points to NIS2 for in-scope cloud computing services. Recital 12 is a recital, not an operative article. This page does not find that YOUR SaaS is in or out of CRA.
| Point | CRA Article 14 | NIS2 Article 23 | DORA Article 19 |
|---|---|---|---|
| Who | Manufacturer of a product with digital elements (and, separately, open-source software stewards under Article 24(3) to the extent that article states). | Essential or important entities as transposed. | Financial entities in DORA's scope, and as DORA provides for ICT third-party service providers. |
| Trigger | Actively exploited vulnerability, or severe incident having an impact on the security of the product. | Significant incident having an impact on the provision of services. | Major ICT-related incident (classification under Article 18 / the RTS). |
| 24-hour mark | Early warning from becoming aware (Article 14(2)(a) or 14(4)(a)). | Early warning from becoming aware of the significant incident (Article 23(4)(a)). | Initial notification from classification, on the RTS time limit — not CRA's awareness start. The reporting-deadlines page on this site is the DORA row. |
| 72-hour mark | Vulnerability or incident notification from becoming aware (Article 14(2)(b) or 14(4)(b)). | Incident notification from becoming aware (Article 23(4)(b)). | Intermediate report from submission of the initial notification, not from awareness. |
| Later mark | Actively exploited: 14 days after a corrective or mitigating measure is available. Severe incident: one month after the 72-hour incident notification. Those two CRA marks are not one number. | Final report not later than one month after the incident notification. Not 14 days. | Final report no later than one month after the intermediate report (or latest update). Not 14 days. |
| Recipient | CSIRT designated as coordinator and ENISA, via the single reporting platform. | The CSIRT or, where applicable, the competent authority. Not ENISA as the Article 23 filing desk. | The relevant competent authority. Not the CRA Single Reporting Platform. |
Checklist
This is a question list, not a filing, and not YOUR notice. Walk it with counsel. The reporting-deadlines page on this site is the statute table. The reporting-decision-tree page on this site is the branching tree. The which-jurisdictions-apply page on this site is the applicability map.
- Does CRA apply? Manufacturer of a product with digital elements made available on the Union market — Articles 3(1), 3(13) and the scope provisions. This page does not run that test. The obligation-map in-scope mark is not that determination.
- Actively exploited vulnerability under Article 3(42), or severe incident under Article 14(5)? Do not invent a CVE list as the test.
- Awareness (UTC): the minute you currently believe the manufacturer became aware, in Article 14's words. Do not treat reading this page as becoming aware. This page does not find that minute.
- Early warning: 24 hours from becoming aware — Article 14(2)(a) or 14(4)(a). Recipients: the CSIRT designated as coordinator and ENISA via the single reporting platform. Do not blend this with the 72-hour notification.
- Notification: 72 hours from becoming aware — Article 14(2)(b) or 14(4)(b). Same start event as the 24-hour early warning.
- Final report, actively-exploited track: 14 days after a corrective or mitigating measure is available — Article 14(2)(c). Not from awareness.
- Final report, severe-incident track: one month after submission of the 72-hour incident notification — Article 14(4)(c). Not 14 days. Do not convert 'one month' into hours.
- Users: Article 14(8) is a different stream from the CSIRT/ENISA filings. The who-to-notify page on this site is the recipient-class map.
- Platform: ENISA has published that the SRP is scheduled to be operational from 11 September 2026. As of 8 September 2026 the production portal is not yet live. Verify ENISA's current SRP page before you treat a URL as a filing desk.
- Document the assessment, including a no-notification decision. The document-your-decision page on this site is the decision record. This page does not keep YOUR file.
Glossary
These words are used as the cited text uses them. This page does not apply them to YOUR facts.
| Term | How this page uses it |
|---|---|
| Manufacturer | Article 3(13). Not a product mark. Not a finding that YOU are a manufacturer. |
| Product with digital elements | Article 3(1): a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately. |
| Actively exploited vulnerability | Article 3(42): reliable evidence that a malicious actor has exploited it in a system without permission of the system owner. Not 'any CVE'. Not a KEV listing by itself. |
| Severe incident | Article 14(5) qualitative test on an incident having an impact on the security of the product. Not NIS2's significant incident. |
| Early warning | Article 14(2)(a) or 14(4)(a): 24 hours from becoming aware. Not the 72-hour notification, and not NIS2 Article 23's early warning. |
| Vulnerability / incident notification | Article 14(2)(b) or 14(4)(b): 72 hours from becoming aware. Not the 14-day final report. |
| 14-day final report | Article 14(2)(c) on the actively-exploited track: no later than 14 days after a corrective or mitigating measure is available. Not from awareness. Not the severe-incident one-month final report. |
| CSIRT designated as coordinator | Article 3(51), designated pursuant to Article 12(1) of Directive (EU) 2022/2555. Article 14 recipient, with ENISA, via the single reporting platform. |
| Single reporting platform | Article 16 platform established by ENISA. Scheduled, per ENISA and the Commission, to be operational from 11 September 2026. Not live as of last verification on 8 September 2026. |
| Becoming aware | Article 14 clock-start for the 24-hour and 72-hour stages. This page does not find that minute. Recorded awareness in the signed-in ladder is a human determination the platform must not backdate. |
| Open-source software steward | Article 3(14). Article 24(3) applies selected Article 14 duties to the extent that article states. ENISA's SRP FAQ treats those steward duties as applying from 11 December 2027 — agency guidance on Article 71(2), not a rewrite of Article 14. |
Where this shows up in ShipReady Metrics
The signed-in app does not decide that CRA applies, does not decide that you are a manufacturer, does not decide that a finding is an actively exploited vulnerability or a severe incident, does not start an Article 14 clock, and does not submit to ENISA or a CSIRT. None of the surfaces below is 'CRA applies', 'this clock has started', or an instruction to submit a filing.
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organisation has classified as CRA-in-scope. That is one product tracker for the CRA actively-exploited ladder. The 24-hour / 72-hour clocks run from the organisation's recorded awareness — a human determination the platform must not backdate. A KEV match timestamp is disclosure, not the clock. It does not start an Article 14 clock. It is not a determination that CRA applies. A named human still submits.
The obligation map lists frameworks the organisation has marked in-scope, including CRA if that mark is set. That mark is not a determination that CRA applies, not a determination that you are a manufacturer of a product with digital elements, and not a legal opinion. The cyber risk register lives under Security. None of those surfaces files an Article 14 early warning, notification, or final report with a CSIRT or ENISA.
Illustrative CRA test-data views are for internal testers. They are not a customer path and not a filing desk. This page does not document a public demo URL.
Primary sources (last verified 8 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/2847 of 23 October 2024 (Cyber Resilience Act), Articles 3, 14, 16, 24, 69(3) and 71(2), is a legal requirement only if it applies. Article 14 reporting applies from 11 September 2026 (Article 71(2)). Article 69(3) applies those Article 14 duties to in-scope products placed on the market before 11 December 2027. Commission Delegated Regulation (EU) 2026/881 is the delegated act on delaying dissemination under Article 16(2) — not Article 14 itself. The European Commission's CRA reporting page and CRA implementation FAQs / guidance are Commission materials, not the regulation. ENISA's Single Reporting Platform page, SRP FAQ (updated 7 September 2026), SRP Glossary and factsheet are agency guidance on the Article 16 platform, not the regulation. As of 8 September 2026 ENISA has published that the SRP is scheduled to be operational from 11 September 2026; the production portal is not confirmed live on the verification date. Directive (EU) 2022/2555 Article 23 is a different instrument; the NIS2 incident-reporting guide is on this site. Regulation (EU) 2022/2554 Article 19 is a different instrument; the DORA incident-reporting guide is on this site. These are not a complete world list. Not legal advice.
The reporting-deadlines page on this site is the statute table of clocks. The reporting-decision-tree page on this site is the branching tree. The which-jurisdictions-apply page on this site is the applicability map. The who-to-notify page on this site is the recipient-class map. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The do-I-have-to-report page on this site is the class map. The prepare-regulatory-report page on this site is the field checklist. The GDPR breach-notification guide on this site is Articles 33–34. The NIS2 incident-reporting guide on this site is Article 23. The DORA incident-reporting guide on this site is Articles 18–19. The UK GDPR jurisdiction guide on this site is Articles 33–34 to the Commissioner. The US-state-laws guide on this site is the representative high-variance comparison. The SEC cyber-disclosure guide on this site is Form 8-K Item 1.05 and Item 106. A dedicated HIPAA, Canada PIPEDA, Australia NDB, India DPDP / CERT-In, and UAE/Dubai guide is not on this site yet. Naming them is not a link.
Frequently asked questions
When must you report under CRA Article 14?
If CRA applies, Article 14 sets a 24-hour early warning and a 72-hour notification from the manufacturer becoming aware, on both the actively-exploited and severe-incident tracks. The actively-exploited final report is no later than 14 days after a corrective or mitigating measure is available. The severe-incident final report is within one month after the 72-hour incident notification. Those marks are not one number. Article 14 applies from 11 September 2026. Last verified 8 September 2026. Not legal advice.
Is this legal advice?
No. It is a jurisdiction guide distilled from Regulation (EU) 2024/2847 Articles 3, 14, 16, 24, 69(3) and 71(2), with ENISA Single Reporting Platform materials and Commission CRA pages labelled as guidance, not the regulation. Whether CRA applies, whether you are a manufacturer, whether you have become aware, and whether a clock has started are legal questions for counsel on your facts. This page does not start a reporting clock.
Does ShipReady file CRA reports?
No. The signed-in app does not file with a CSIRT or ENISA, does not start an Article 14 clock, and does not decide that CRA applies or that you are a manufacturer. Compliance → CRA reporting tracks the Article 14 24-hour / 72-hour / 14-day ladder from recorded awareness (and recorded measure availability for the 14-day mark) for findings the org classified as CRA-in-scope. A named human still submits. The obligation map is frameworks marked in-scope, not a legal opinion.
Does the in-app ladder start my Art. 14 clock?
No. The signed-in Compliance → CRA reporting tracker runs from recorded awareness for findings the organisation classified as CRA-in-scope. Recorded awareness is a human determination the platform must not backdate. Opening the ladder, classifying a finding as CRA-in-scope, or reading this page does not start the Article 14 clock. A named human still files with the CSIRT and ENISA via the single reporting platform.
Are the 24-hour, 72-hour, and 14-day marks the same deadline?
No. Article 14(2)(a) is 24 hours from becoming aware (early warning). Article 14(2)(b) is 72 hours from becoming aware (vulnerability notification). Article 14(2)(c) is 14 days after a corrective or mitigating measure is available (final report on the actively-exploited track). The severe-incident final report is one month after the 72-hour notification, not 14 days. This page does not average those marks.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.