Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What does CRA Article 14 require you to report, and when?
Updated
Article 14 of Regulation (EU) 2024/2847 sets a 24-hour early warning, a 72-hour notification, and a 14-day final report on the actively-exploited track, from 11 September 2026. This CRA-cluster overview is not legal advice and does not start a clock.
CRA-cluster Article 14 overview, last verified 8 September 2026 against Regulation (EU) 2024/2847 Articles 3, 14, 16, 69(3) and 71(2), ENISA's Single Reporting Platform materials (agency guidance, not the regulation), and the European Commission's CRA reporting page (Commission materials, not the regulation). It is not legal advice, not a filing, not a determination that the CRA applies, and not a substitute for counsel. It does not invent a second set of clocks. The statute-clock Article 14 guide on this site is the ladder under breach reporting.
This is the CRA-cluster overview, not the statute-clock page
Audience: a CISO, product, engineering, or compliance lead at an organisation that might be a manufacturer of products with digital elements under Regulation (EU) 2024/2847. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the CRA applies, that you are a manufacturer, that a product with digital elements has been made available on the Union market, that you have become aware, or that a filing is due.
This page is the CRA-cluster overview of Article 14. The statute-clock Article 14 guide on this site is the CRA Article 14 page under breach reporting. That page is the ladder already on this site: 24-hour early warning, 72-hour notification, 14-day final report on the actively-exploited track, and the severe-incident one-month final report. Open it for the stages. This cluster page does not copy that ladder and does not invent a second set of clocks. Those two pages agree on the marks. Last verified 8 September 2026. Not legal advice.
- Statute versus guidance: Articles 3, 14, 16, 69(3) and 71(2) are legal requirements only if they apply. ENISA's Single Reporting Platform materials are agency guidance, not the regulation. The Commission's CRA reporting page and implementation FAQs are Commission materials, not the regulation. This page quotes which kind of text it is relying on.
- The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page. Article 14 reporting is a manufacturer duty under Article 14; this page does not find that YOU are a manufacturer.
- A dedicated products-in-scope, SaaS-scope, 24-hour early warning, 72-hour notification, final-report, actively-exploited, and reporting-decision-tree guide is not on this site yet. Naming them is not a link.
- The signed-in CRA ladder tracks recorded awareness for findings the organisation classified as CRA-in-scope. That tracker does not start an Article 14 clock, does not decide that the CRA applies, and does not file with a CSIRT or ENISA. A named human still submits.
How Article 14 sits in the CRA cluster
Article 14 is one chapter of the CRA cluster, not the whole regulation. Who is covered, which products are in scope, and whether a SaaS path is a product with digital elements are prior questions. This page does not run those tests. Last verified 8 September 2026. Not legal advice.
| Cluster question | What it is for | Where it lives on this site | Last verified |
|---|---|---|---|
| What is the CRA? | Regulation (EU) 2024/2847: product classes, CE marking, phased dates. | The CRA overview on this site is the pillar page. | 8 September 2026 |
| Who is covered? | Manufacturer, authorised representative, importer, distributor, open-source software steward. Article 14 is a manufacturer notification duty. | The who-is-covered guide on this site is the economic-operator roles page. This page does not classify YOU. | 8 September 2026 |
| Which products are in scope? | Products with digital elements; default / important class I & II / critical. | A dedicated products-in-scope guide is not on this site yet. Naming it is not a link. | 8 September 2026 |
| Is SaaS in scope? | Remote data-processing solutions versus a standalone service. Recital 12 is a recital, not an operative article. | A dedicated SaaS-scope guide is not on this site yet. Naming it is not a link. | 8 September 2026 |
| What does Article 14 require, and when? | Two triggers, a 24-hour / 72-hour / 14-day ladder on the actively-exploited track, from 11 September 2026. | This cluster overview. The statute-clock page under breach reporting is the ladder. They agree. This page does not invent a second set of clocks. | 8 September 2026 |
Applicability — Article 71(2), not YOUR date
Last verified 8 September 2026 against Article 71(2) on EUR-Lex. Article 71(2): this Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026, and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026. Article 14 reporting is not delayed until full application in December 2027.
Article 69(3): by way of derogation from Article 69(2), the obligations laid down in Article 14 shall apply to all products with digital elements that fall within the scope of this Regulation that have been placed on the market before 11 December 2027. This block is not a determination that YOU are in scope, that a named product is a product with digital elements, or that a clock has started.
| What applies | Date in the regulation | Kind of text | Last verified |
|---|---|---|---|
| Article 14 reporting obligations of manufacturers | 11 September 2026 | Article 71(2), second subparagraph. Legal requirement. This page does not start that clock. | 8 September 2026 |
| Article 14 as applied to in-scope products placed on the market before 11 December 2027 | The Article 14 duties apply to those products (derogation from Article 69(2)). | Article 69(3). Legal requirement. This page does not find that YOUR product was placed on the market. | 8 September 2026 |
| The rest of the Regulation, including essential cybersecurity requirements | 11 December 2027 | Article 71(2), first subparagraph. Not the Article 14 reporting ladder. | 8 September 2026 |
Two triggers — actively exploited versus severe incident
Article 14 has two mandatory tracks. They share a 24-hour early warning and a 72-hour notification. They diverge at the final report. This page does not invent a CVE list, a KEV list, or a severity score that the article does not state. The statute-clock page on this site is the full trigger table. Last verified 8 September 2026. Not legal advice.
- Do not invent a CVE catalogue as the trigger. Article 14(1) is awareness of an actively exploited vulnerability contained in the product, as Article 3(42) defines that term.
- A KEV match, a scanner alert, or a customer report may be how you learn a fact. None of those events is, by itself, the legal finding that you have become aware. Counsel maps YOUR facts.
- The 14-day mark on the actively-exploited track is not the one-month mark on the severe-incident track. Those two final-report marks are not one number.
| Trigger | What the text says | Kind of text | Last verified |
|---|---|---|---|
| Actively exploited vulnerability — Article 14(1) | A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator and to ENISA, via the single reporting platform established pursuant to Article 16. | Legal requirement — Article 14(1). Only if the CRA applies. | 8 September 2026 |
| Actively exploited vulnerability — definition | Article 3(42): a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner. Article 3(40) and 3(41) are different definitions. | Legal requirement — Article 3(40)–(42). This page does not find that YOUR CVE is actively exploited. | 8 September 2026 |
| Severe incident — Article 14(3) | A manufacturer shall notify any severe incident having an impact on the security of the product with digital elements that it becomes aware of simultaneously to the same CSIRT and to ENISA, via the same platform. | Legal requirement — Article 14(3). | 8 September 2026 |
| Severe — Article 14(5) | An incident having an impact on the security of the product with digital elements shall be considered to be severe where it negatively affects or is capable of negatively affecting the ability of the product to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions; or it has led or is capable of leading to the introduction or execution of malicious code in the product or in the network and information systems of a user of the product. | Legal requirement — Article 14(5). Qualitative. This page does not score YOUR incident. | 8 September 2026 |
Timeline table — Article 14 limbs, not YOUR clock
The 24-hour early warning, the 72-hour notification, and the 14-day final report are three distinct marks. This page does not average them, does not round 72 hours to three days, and does not treat 14 days as the severe-incident final report. Clock-start is the event the cited limb names. Last verified 8 September 2026. Not legal advice. This table does not start a clock. It does not invent a second set of clocks. The statute-clock page on this site is the full stage table.
- Recipients: the CSIRT designated as coordinator and ENISA, via the single reporting platform (Articles 14(1), 14(7) and 16). This page does not name YOUR CSIRT and does not run the Article 14(7) cascade.
- Article 14(8) is a different stream: inform impacted users after becoming aware. It is not converted into a 24-hour, 72-hour, or 14-day count on this page.
- A dedicated 24-hour early-warning, 72-hour notification, final-report, and actively-exploited guide is not on this site yet. Naming them is not a link. The statute-clock page on this site is the ladder already published.
| Limb | Deadline (statutory words) | Clock starts | Source | Last verified |
|---|---|---|---|---|
| Early warning — both tracks | Without undue delay and in any event within 24 hours of the manufacturer becoming aware of it. | The manufacturer becoming aware of the actively exploited vulnerability or the severe incident. This page does not find that you have become aware, and it does not start the 24 hours. | Article 14(2)(a) and Article 14(4)(a). Legal requirement. | 8 September 2026 |
| Notification — both tracks | Without undue delay and in any event within 72 hours of the manufacturer becoming aware. | The same becoming-aware event as the 24-hour early warning — not a second, later start. The 24-hour band and the 72-hour band are not averaged into one number. | Article 14(2)(b) and Article 14(4)(b). Legal requirement. | 8 September 2026 |
| Final report — actively-exploited track | No later than 14 days after a corrective or mitigating measure is available. | Measure availability — not awareness. The 14-day mark is not the 24-hour mark and not the 72-hour mark. This page does not find that a measure is available. | Article 14(2)(c). Legal requirement. | 8 September 2026 |
| Final report — severe-incident track | Within one month after the submission of the incident notification under Article 14(4)(b). | Submission of that 72-hour incident notification — not awareness, and not measure availability. This one-month mark is not the 14-day mark on the actively-exploited track. | Article 14(4)(c). Legal requirement. | 8 September 2026 |
| When Article 14 itself applies | Article 14 shall apply from 11 September 2026. | Application date in Article 71(2) — not a reporting clock, and not YOUR clock. | Article 71(2), second subparagraph. Legal requirement. | 8 September 2026 |
Single reporting platform — ENISA guidance, not the article
Article 16(1): for the notifications referred to in Article 14(1) and (3) and Article 15(1) and (2), a single reporting platform shall be established by ENISA. That is the legal requirement.
What ENISA and the Commission currently publish, last verified 8 September 2026: ENISA's Single Reporting Platform materials and the Commission's CRA reporting page state that the platform is scheduled to be operational from 11 September 2026, coinciding with Article 14 application. Those pages are guidance, not the regulation. This page does not treat an ENISA FAQ as starting YOUR clock, and does not treat a named portal URL as proof the production system is live on the verification date.
A dedicated where-to-submit, ENISA-workflow, and CSIRT guide is not on this site yet. Naming them is not a link. The statute-clock page on this site records what ENISA has published about the portal as of last verification.
Legal requirement versus Commission and ENISA guidance
The table below labels each text. Do not treat guidance as the article, and do not treat the article as optional because a FAQ exists. Last verified 8 September 2026. Not legal advice.
| Text | What it is | What this page does not do |
|---|---|---|
| Regulation (EU) 2024/2847 Articles 3, 14, 16, 69(3), 71(2) | Legal requirement — the regulation, only if it applies. | Does not apply those articles to YOU. |
| European Commission CRA reporting page and Commission FAQs on CRA implementation | Commission materials. Guidance, not the regulation. | Does not treat a Commission FAQ as a substitute for Article 14. |
| ENISA Single Reporting Platform page and SRP FAQ | Agency guidance on the platform ENISA establishes under Article 16. Not the regulation. | Does not treat an ENISA FAQ as starting YOUR clock. |
What to do now
As of last verification on 8 September 2026, Article 14 applies from 11 September 2026 — three days from that verification date. The list below is operational preparation. It is not a determination that the CRA applies to YOU, that you are a manufacturer, or that a reporting clock has started. Walk it with counsel.
- Ask counsel whether YOU are a manufacturer of a product with digital elements made available on the Union market. This page does not run that test. The who-is-covered guide on this site is the roles page. Marking CRA in an obligation map is not that determination.
- If counsel says Article 14 may apply, open the statute-clock Article 14 guide on this site for the 24-hour / 72-hour / 14-day ladder. This cluster overview does not start that clock and does not invent a second set of clocks.
- Decide how the organisation will record the minute it becomes aware of an actively exploited vulnerability or a severe incident, in UTC. Do not treat reading this page as becoming aware. The signed-in ladder, if you use it, tracks recorded awareness — it does not decide that minute.
- Do not paste NIS2's one-month final report onto CRA's 14-day actively-exploited final report. Do not paste CRA's 14-day mark onto the severe-incident one-month final report. Do not treat a KEV listing as automatic becoming-aware.
- A dedicated products-in-scope, SaaS-scope, 24-hour, 72-hour, final-report, and actively-exploited guide is not on this site yet. Naming them is not a link.
Checklist
This is a question list, not a filing, and not YOUR notice. Walk it with counsel. The statute-clock Article 14 guide on this site is the ladder. The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the roles page.
- Does the CRA apply? Manufacturer of a product with digital elements made available on the Union market. This page does not run that test.
- Actively exploited vulnerability under Article 3(42), or severe incident under Article 14(5)? Do not invent a CVE list as the test.
- Awareness (UTC): the minute you currently believe the manufacturer became aware, in Article 14's words. Do not treat reading this page as becoming aware. This page does not find that minute.
- Early warning: 24 hours from becoming aware — Article 14(2)(a) or 14(4)(a). Recipients: the CSIRT designated as coordinator and ENISA via the single reporting platform.
- Notification: 72 hours from becoming aware — Article 14(2)(b) or 14(4)(b). Same start event as the 24-hour early warning.
- Final report, actively-exploited track: 14 days after a corrective or mitigating measure is available — Article 14(2)(c). Not from awareness. Not the 24-hour mark.
- Final report, severe-incident track: one month after submission of the 72-hour incident notification — Article 14(4)(c). Not 14 days.
- Article 14 from 11 September 2026 (Article 71(2)). This page does not start that clock.
- Document the assessment, including a no-notification decision. This page does not keep YOUR file.
Where this shows up in ShipReady Metrics
The signed-in app does not decide that the CRA applies, does not decide that you are a manufacturer, does not decide that a finding is an actively exploited vulnerability or a severe incident, does not start an Article 14 clock, and does not submit to ENISA or a CSIRT. None of the surfaces below is 'CRA applies', 'this clock has started', or an instruction to submit a filing.
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organisation has classified as CRA-in-scope. That is one product tracker for the CRA actively-exploited ladder. The 24-hour / 72-hour clocks run from the organisation's recorded awareness — a human determination the platform must not backdate. A KEV match timestamp is disclosure, not the clock. It does not start an Article 14 clock. It is not a determination that the CRA applies. A named human still submits.
The obligation map lists frameworks the organisation has marked in-scope, including CRA if that mark is set. That mark is not a determination that the CRA applies, not a determination that you are a manufacturer of a product with digital elements, and not a legal opinion. The cyber risk register lives under Security. None of those surfaces files an Article 14 early warning, notification, or final report with a CSIRT or ENISA.
This page does not document a public demo URL. There is no public CRA demo path. ENISA's Single Reporting Platform is guidance on the Article 16 platform, not a submit button in this product.
Primary sources (last verified 8 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/2847 of 23 October 2024 (Cyber Resilience Act), Articles 3, 14, 16, 69(3) and 71(2), is a legal requirement only if it applies. Article 14 reporting applies from 11 September 2026 (Article 71(2)). Article 69(3) applies those Article 14 duties to in-scope products placed on the market before 11 December 2027. The European Commission's CRA reporting page and CRA implementation FAQs are Commission materials, not the regulation. ENISA's Single Reporting Platform page and SRP FAQ are agency guidance on the Article 16 platform, not the regulation. Directive (EU) 2022/2555 Article 23 is a different instrument; the NIS2 incident-reporting guide is on this site. Regulation (EU) 2022/2554 Articles 18–19 are a different instrument; the DORA incident-reporting guide is on this site. These are not a complete world list. Not legal advice.
The statute-clock Article 14 guide on this site is the live ladder under breach reporting. The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page. A dedicated products-in-scope, SaaS-scope, 24-hour early-warning, 72-hour notification, final-report, actively-exploited, and reporting-decision-tree guide is not on this site yet. Naming them is not a link.
Frequently asked questions
Is this legal advice?
No. It is a CRA-cluster overview distilled from Regulation (EU) 2024/2847 Articles 3, 14, 16, 69(3) and 71(2), with ENISA Single Reporting Platform materials and Commission CRA pages labelled as guidance, not the regulation. Whether the CRA applies, whether you are a manufacturer, whether you have become aware, and whether a clock has started are legal questions for counsel on your facts. This page does not start a reporting clock.
Does ShipReady file Article 14 reports?
No. The signed-in app does not file with a CSIRT or ENISA, does not start an Article 14 clock, and does not decide that the CRA applies or that you are a manufacturer. Compliance → CRA reporting tracks recorded awareness for findings the organisation classified as CRA-in-scope. A named human still submits. The obligation map is frameworks marked in-scope, not a legal opinion.
Is this the same page as the breach-reporting CRA guide?
No. The breach-reporting CRA page on this site is the statute-clock guide: the 24-hour, 72-hour, and 14-day ladder in full. This page is the CRA-cluster overview of how Article 14 sits next to who-is-covered, products-in-scope, and SaaS-scope. Those two pages agree on the marks. This page does not invent a second set of clocks.
Is the 14-day final report the same as the 24-hour early warning?
No. Article 14(2)(a) is 24 hours from becoming aware (early warning). Article 14(2)(b) is 72 hours from becoming aware (vulnerability notification). Article 14(2)(c) is 14 days after a corrective or mitigating measure is available (final report on the actively-exploited track). The severe-incident final report is one month after the 72-hour notification, not 14 days. This page does not average those marks.
Does the in-app ladder start my Art. 14 clock?
No. The signed-in Compliance → CRA reporting tracker runs from recorded awareness for findings the organisation classified as CRA-in-scope. Recorded awareness is a human determination the platform must not backdate. Opening the ladder, classifying a finding as CRA-in-scope, or reading this page does not start the Article 14 clock. A named human still files with the CSIRT and ENISA via the single reporting platform.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.