Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What is the CRA Article 14 24-hour early warning?
Updated
The CRA 24-hour early warning is an Article 14 notification to the CSIRT designated as coordinator and to ENISA via the single reporting platform, without undue delay and in any event within 24 hours of the manufacturer becoming aware.
CRA 24-hour early warning guide, last verified 8 September 2026 against Regulation (EU) 2024/2847 Articles 3(42), 14(1)–(5), 14(7), 16 and 71(2), ENISA's Single Reporting Platform FAQ (updated 8 September 2026 — agency guidance, not the regulation), and the European Commission's CRA reporting page. It is not legal advice, not a filing, not a determination that the manufacturer has become aware, and does not start a clock.
This is the 24-hour early warning, not YOUR clock
Audience: an incident responder, CISO, or counsel at an organisation that might be a manufacturer of products with digital elements under Regulation (EU) 2024/2847. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the CRA applies, that you are a manufacturer, that a product with digital elements has been made available on the Union market, that you have become aware, or that a filing is due.
The CRA is Regulation (EU) 2024/2847 of 23 October 2024, OJ L 2024/2847, 20.11.2024. ELI: http://data.europa.eu/eli/reg/2024/2847/2024-11-20. Article 71(2): this Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026. Last verified 8 September 2026. Not legal advice.
- Statute versus guidance: Articles 14(1)–(5), 14(7), 16 and 71(2) are legal requirements only if they apply. ENISA's Single Reporting Platform FAQ (updated 8 September 2026), SRP Glossary, and the Commission's CRA reporting page are guidance, not the regulation. This page quotes which kind of text it is relying on.
- The statute-clock Article 14 guide on this site is the CRA Article 14 page under breach reporting — the full ladder. The CRA-cluster Article 14 overview on this site is the cluster reporting page. The CRA overview on this site is the pillar page. The ENISA-workflow guide on this site is the platform-flow page. The 72-hour notification guide on this site is the second-rung page. A dedicated incident-example guide is not on this site yet. Naming it is not a link.
- The signed-in CRA ladder tracks recorded awareness for findings the organisation classified as CRA-in-scope. That tracker does not start an Article 14 clock, does not decide that the CRA applies, and does not file with a CSIRT or ENISA. A named human still submits.
Two triggers, one 24-hour limb — do not collapse them
Article 14 has two mandatory tracks. They share a 24-hour early-warning limb. They are not one trigger. This page does not collapse an actively exploited vulnerability into a severe incident, or the reverse. Last verified 8 September 2026. Not legal advice.
- The 24-hour band is the same length on both tracks. The statutory content of the early warning is not the same. Article 14(2)(a) names Member States, where applicable. Article 14(4)(a) names, at least, whether the incident is suspected of being caused by unlawful or malicious acts, and Member States, where applicable.
- Do not paste GDPR 'awareness' or a 'discovery' test onto Article 14. The regulation's words are 'the manufacturer becoming aware of it'. This page does not convert those words.
| Limb | What the cited text says | Kind of text | What this page does not do |
|---|---|---|---|
| Actively exploited vulnerability — Article 14(1) and 14(2)(a) | Article 14(1): a manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. The manufacturer shall notify that actively exploited vulnerability via the single reporting platform established pursuant to Article 16. Article 14(2)(a): an early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available. | Legal requirement — Articles 14(1) and 14(2)(a). Only if the CRA applies. | Does not find that YOUR CVE is an actively exploited vulnerability. Does not start the 24 hours. |
| Actively exploited vulnerability — definition | Article 3(42): a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner. | Legal requirement — Article 3(42). | Does not treat a KEV listing, a scanner alert, or a customer report as, by itself, that finding. |
| Severe incident — Article 14(3) and 14(4)(a) | Article 14(3): a manufacturer shall notify any severe incident having an impact on the security of the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. The manufacturer shall notify that incident via the single reporting platform established pursuant to Article 16. Article 14(4)(a): an early warning notification of a severe incident having an impact on the security of the product with digital elements, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, including at least whether the incident is suspected of being caused by unlawful or malicious acts, which shall also indicate, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available. | Legal requirement — Articles 14(3) and 14(4)(a). | Does not score YOUR incident as severe. Does not start the 24 hours. |
| Severe — Article 14(5) | An incident having an impact on the security of the product with digital elements shall be considered to be severe where: (a) it negatively affects or is capable of negatively affecting the ability of a product with digital elements to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions; or (b) it has led or is capable of leading to the introduction or execution of malicious code in a product with digital elements or in the network and information systems of a user of the product with digital elements. | Legal requirement — Article 14(5). Qualitative. | Does not apply that test to YOUR facts. |
Clock-start — the manufacturer becoming aware
Article 14(2)(a) and Article 14(4)(a) start the 24 hours from the manufacturer becoming aware of the actively exploited vulnerability, or of the severe incident. That is the statutory clock-start. This page does not find that minute. It does not start the 24 hours. Last verified 8 September 2026. Not legal advice.
| Event | What the cited text says | Kind of text | What this page does not do |
|---|---|---|---|
| Manufacturer becoming aware — actively exploited track | Article 14(2)(a): without undue delay and in any event within 24 hours of the manufacturer becoming aware of it. | Legal requirement — Article 14(2)(a). | Does not find that YOU have become aware. Does not convert 'becoming aware' into 'discovery'. |
| Manufacturer becoming aware — severe-incident track | Article 14(4)(a): without undue delay and in any event within 24 hours of the manufacturer becoming aware of it. | Legal requirement — Article 14(4)(a). | Does not paste a GDPR Article 33 awareness test onto Article 14. |
| Recorded awareness in the signed-in ladder | The product tracks a human-recorded aware-at for findings the organisation classified as CRA-in-scope. A KEV match timestamp is disclosure, not the clock. | Product behaviour — not the regulation. | Does not start the statutory clock. Does not treat an in-scope mark as awareness. |
Recipients — CSIRT designated as coordinator and ENISA
Article 14(1) and Article 14(3): simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7, and to ENISA, via the single reporting platform established pursuant to Article 16. Article 14(7): the notifications referred to in paragraphs 1 and 3 of this Article shall be submitted via the single reporting platform referred to in Article 16 using one of the electronic notification end-points referred to in Article 16(1). The notification shall be submitted using the electronic notification end-point of the CSIRT designated as coordinator of the Member State where the manufacturers have their main establishment in the Union and shall be simultaneously accessible to ENISA. Last verified 8 September 2026. Not legal advice.
Article 16(1): for the purposes of the notifications referred to in Article 14(1) and (3) and Article 15(1) and (2) and in order to simplify the reporting obligations of manufacturers, a single reporting platform shall be established by ENISA. That is the legal requirement. ENISA's SRP FAQ (updated 8 September 2026) is agency guidance on that platform, not the regulation. ENISA FAQ 15 (guidance) states that no API will be provided at the initial release.
Required-fields checklist — statute versus ENISA platform fields
The statutory minimum of the early warning is what Article 14(2)(a) and Article 14(4)(a) name. ENISA's SRP FAQ 16 table (updated 8 September 2026) lists additional platform fields as required at the 24-hour step. Those extra fields are agency guidance, not the regulation. Last verified 8 September 2026. Not legal advice. This table is not YOUR filing.
| Field | What the cited text says | Kind of text | What this page does not do |
|---|---|---|---|
| Recipients | Simultaneously to the CSIRT designated as coordinator and to ENISA, via the single reporting platform. | Legal requirement — Articles 14(1), 14(3), 14(7) and 16. | Does not name YOUR CSIRT. Does not submit. |
| Timing | Without undue delay and in any event within 24 hours of the manufacturer becoming aware of it. | Legal requirement — Article 14(2)(a) or 14(4)(a). | Does not start that 24 hours. |
| Member States where the product has been made available (where applicable) | Article 14(2)(a) and Article 14(4)(a): indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available. | Legal requirement — Article 14(2)(a) and 14(4)(a). | Does not map YOUR distribution. |
| Suspected unlawful or malicious acts (severe-incident track only) | Article 14(4)(a): including at least whether the incident is suspected of being caused by unlawful or malicious acts. | Legal requirement — Article 14(4)(a). Not an Article 14(2)(a) field. | Does not decide that YOUR incident was malicious. |
| Notification type, notification level, title, summary, manufacturer name, product name, product version | ENISA SRP FAQ 16 table lists these as required at the 24-hour early warning. FAQ 16 also lists date/time when you become aware as required on each track. | Agency guidance — ENISA SRP FAQ 16 (updated 8 September 2026), not Article 14. | Does not treat an ENISA required-field mark as rewriting Article 14(2)(a) or 14(4)(a). |
| CVE ID, EUVD ID, product class, attack vector, mitigating measure expected shortly | ENISA SRP FAQ 16 table lists these as optional at the 24-hour early warning. | Agency guidance — ENISA SRP FAQ 16. Not the statutory minimum. | Does not invent a CVE as the Article 14(2)(a) trigger. |
| General nature of the exploit, corrective or mitigating measures, sensitivity | Named in Article 14(2)(b) and Article 14(4)(b) for the 72-hour notification, unless already provided. Not named in Article 14(2)(a) or 14(4)(a). | Legal requirement of the 72-hour limb — not the 24-hour statutory minimum. | Does not blend the 24-hour early warning into the 72-hour notification. |
Worked timing example — illustration, not YOUR clock
The table below is an illustration. It uses a hypothetical recorded-awareness instant. It is not YOUR clock. It is not a determination that anyone has become aware. It does not start 24 hours. Last verified 8 September 2026. Not legal advice.
| Instant (illustration) | What it represents | Kind of text | What this page does not do |
|---|---|---|---|
| 15 September 2026, 09:00 UTC | A hypothetical recorded-awareness instant after Article 14 applies (Article 71(2): Article 14 shall apply from 11 September 2026). | Illustration — not a filing, not a finding. | Does not find that YOU became aware at this instant. Does not start the statutory clock. |
| 16 September 2026, 09:00 UTC | Twenty-four hours later than that hypothetical instant. Article 14(2)(a) and 14(4)(a) say without undue delay and in any event within 24 hours of the manufacturer becoming aware of it. | Illustration of the statutory 24-hour band — not a due-date for YOU. | Does not file an early warning. Does not run a countdown widget. |
| Same start for the 72-hour notification | Article 14(2)(b) and 14(4)(b) also run from the manufacturer becoming aware — not from the early-warning filing. The 24-hour band and the 72-hour band are not averaged into one number. | Legal requirement of the 72-hour limb. The 72-hour notification guide on this site is the second-rung page. | Does not start 72 hours. Does not treat the early warning as discharging the 72-hour notification. |
Legal requirement versus Commission and ENISA guidance
The table below labels each text. Do not treat guidance as the article, and do not treat the article as optional because a FAQ exists. Last verified 8 September 2026. Not legal advice.
| Text | What it is | What this page does not do |
|---|---|---|
| Regulation (EU) 2024/2847 Articles 3(42), 14(1)–(5), 14(7), 16, 71(2) | Legal requirement — the regulation, only if it applies. | Does not apply those articles to YOU. |
| European Commission CRA reporting page | Commission materials. Guidance, not the regulation. | Does not treat a Commission summary as a substitute for Article 14(2)(a) or 14(4)(a). |
| ENISA Single Reporting Platform FAQ (updated 8 September 2026), SRP Glossary, FAQ 16 field table | Agency guidance on the Article 16 platform. FAQ 16 adds required platform fields (title, summary, manufacturer name, product name, product version, notification type, notification level, date/time of becoming aware) beyond the Article 14(2)(a) and 14(4)(a) statutory minimum. | Does not treat an ENISA required-field mark as the article. Does not treat a named portal URL as proof the production system is live on the verification date. |
How this differs from the 72-hour notification
The 24-hour early warning is not the 72-hour notification. Article 14(2)(b) and Article 14(4)(b) are a different limb: unless the relevant information has already been provided, a vulnerability or incident notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware. The 72-hour notification guide on this site is the second-rung page. Last verified 8 September 2026. Not legal advice.
- Same clock-start: the manufacturer becoming aware. Not a second, later start when the early warning is filed.
- Different content: the 72-hour limb names general information, the general nature of the exploit or incident, corrective or mitigating measures, measures users can take, and, where applicable, sensitivity. Those words are not the Article 14(2)(a) / 14(4)(a) statutory minimum.
- The live Article 14 reporting guide on this site is the full ladder, including the 14-day actively-exploited final report and the severe-incident one-month final report. This page does not duplicate that ladder.
Checklist
This is a question list, not a filing, and not YOUR notice. Walk it with counsel. The live Article 14 reporting guide on this site is the ladder. The reporting-deadlines page on this site is the statute table of clocks.
- Does the CRA apply? Manufacturer of a product with digital elements made available on the Union market. This page does not run that test.
- Actively exploited vulnerability under Article 3(42), or severe incident under Article 14(5)? Do not collapse the two tracks.
- Awareness (UTC): the minute the organisation currently records as the manufacturer becoming aware, in Article 14's words. Do not treat reading this page as becoming aware. An in-scope mark is not awareness.
- Early warning: 24 hours from becoming aware — Article 14(2)(a) or 14(4)(a). Recipients: the CSIRT designated as coordinator and ENISA via the single reporting platform.
- Statutory content: Member States where applicable; on the severe-incident track, at least whether suspected of being caused by unlawful or malicious acts. ENISA FAQ 16 extra fields are guidance.
- Do not blend this with the 72-hour notification. The ENISA-workflow guide on this site is the platform-flow page. The 72-hour notification guide on this site is the second-rung page. A dedicated incident-example guide is not on this site yet. Naming it is not a link.
- Document the assessment, including a no-notification decision. This page does not keep YOUR file.
Where this shows up in ShipReady Metrics
The signed-in app does not decide that the CRA applies, does not decide that you are a manufacturer, does not decide that a finding is an actively exploited vulnerability or a severe incident, does not start an Article 14 clock, and does not submit to ENISA or a CSIRT. There is no CSIRT submit button and no ENISA API. None of the surfaces below is 'the clock has started' or an instruction to submit a filing.
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour stage from recorded awareness for findings the organisation classified as CRA-in-scope actively exploited. That tracker does not start the statutory clock. It does not file. A named human still submits. Recorded awareness is a human determination the platform must not backdate. An in-scope mark is not awareness. A KEV match timestamp is disclosure, not the clock.
The obligation map lists frameworks the organisation has marked in-scope, including cra if that mark is set. That mark is not a determination that the CRA applies and is not awareness. The cyber risk register lives under Security. Named-reviewer drafts of ladder text are marked DRAFT; nothing in that surface has been sent to any authority.
This page does not invent a 24-hour countdown widget. The signed-in ladder is a reporting-stage tracker, not a public countdown. This page does not document a public demo URL. There is no public CRA demo path.
Primary sources (last verified 8 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/2847 of 23 October 2024 (Cyber Resilience Act), Articles 3(42), 14(1)–(5), 14(7), 16 and 71(2), is a legal requirement only if it applies. Article 14 applies from 11 September 2026 (Article 71(2)). The European Commission's CRA reporting page is Commission materials, not the regulation. ENISA's Single Reporting Platform FAQ (updated 8 September 2026), SRP Glossary and FAQ 16 field table are agency guidance on the Article 16 platform, not the regulation. These are not a complete world list. Not legal advice.
The CRA overview on this site is the pillar page. The statute-clock Article 14 guide on this site is the live ladder. The CRA-cluster Article 14 overview on this site is the cluster page. The reporting-deadlines page on this site is the statute table of clocks. The NIS2 incident-reporting guide on this site is Article 23. The ENISA-workflow guide on this site is the platform-flow page. The 72-hour notification guide on this site is the second-rung page. A dedicated incident-example guide is not on this site yet. Naming it is not a link.
Frequently asked questions
Is this legal advice?
No. It is a first-rung guide distilled from Regulation (EU) 2024/2847 Articles 14(2)(a) and 14(4)(a), with ENISA Single Reporting Platform materials labelled as guidance, not the regulation. Whether the CRA applies, whether you have become aware, and whether a clock has started are legal questions for counsel on your facts. This page does not start a clock.
Does ShipReady file the early warning?
No. The signed-in app does not file with a CSIRT or ENISA, does not start an Article 14 clock, and does not decide that the CRA applies. There is no CSIRT submit button and no ENISA API. Compliance → CRA reporting tracks recorded awareness for findings the organisation classified as CRA-in-scope. A named human still submits.
Does the product's 24h ladder start the statutory clock?
No. The signed-in Compliance → CRA reporting tracker runs from recorded awareness for findings the organisation classified as CRA-in-scope actively exploited. Recorded awareness is a human determination the platform must not backdate. Opening the ladder, classifying a finding as CRA-in-scope, or reading this page does not start the Article 14 clock. An in-scope mark is not awareness.
Is 24h the same as 72h?
No. Article 14(2)(a) and Article 14(4)(a) are the 24-hour early warning from becoming aware. Article 14(2)(b) and Article 14(4)(b) are the 72-hour notification from the same becoming-aware event, unless the relevant information has already been provided. Those two marks are not averaged. The 72-hour notification guide on this site is the second-rung page.
Does ENISA guidance add extra fields beyond Art. 14?
Yes, as guidance. Article 14(2)(a) names Member States where applicable. Article 14(4)(a) names, at least, whether the incident is suspected of being caused by unlawful or malicious acts, and Member States where applicable. ENISA SRP FAQ 16 (updated 8 September 2026) lists additional required platform fields at the 24-hour step — title, summary, manufacturer name, product name, product version, notification type, notification level, and date/time of becoming aware. That table is agency guidance, not the regulation.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.