Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
Do you need to report this under CRA Article 14?
Last verifiedWalk this table: is it an actively exploited vulnerability or a severe incident, are you the responsible manufacturer, has the clock started, which rung is due, and where does it go. This tree is not legal advice and does not start a clock.
CRA Article 14 reporting decision tree, last verified 9 September 2026 against Regulation (EU) 2024/2847 Articles 3(13), 3(42), 14, 16 and 71(2), the European Commission's CRA reporting page (Commission materials — guidance, not the regulation), and ENISA Single Reporting Platform materials (agency guidance, not the regulation). It is decision logic, not legal advice, not a filing, not a determination that the CRA applies, not a finding that YOU are a manufacturer, and not a substitute for counsel. Walking a row does not start a clock.
This is decision logic, not legal advice
Audience: an incident responder, CISO, or compliance lead at an organisation that might be a manufacturer of products with digital elements under Regulation (EU) 2024/2847. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the CRA applies, that you are a manufacturer, that a product with digital elements has been made available on the Union market, that you have become aware, which rung is due, or that a filing is due.
The table below is the tree. Content pages on this site have no interactive widget. An accessible table — question, if yes, if no, kind of text — is the core artifact, plus this prose fallback. Last verified 9 September 2026. Not legal advice.
- Statute versus guidance: Articles 3(13), 3(42), 14, 16 and 71(2) are legal requirements only if they apply. The Commission's CRA reporting page and implementation FAQs are Commission materials — guidance, not the regulation. ENISA Single Reporting Platform materials are agency guidance, not the regulation. This page quotes which kind of text it is relying on.
- The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page. The CRA-cluster Article 14 overview on this site is the Article 14 hub. The statute-clock Article 14 guide on this site is the CRA Article 14 page under breach reporting — the 24-hour / 72-hour / 14-day ladder. This tree does not invent a second set of clocks. Those pages agree on the marks.
- A dedicated 24-hour early-warning guide is not on this site yet. Naming it is not a link. A dedicated 72-hour notification guide is not on this site yet. Naming it is not a link. A dedicated final-report guide is not on this site yet. Naming it is not a link. A dedicated actively-exploited guide is not on this site yet. Naming it is not a link.
- The reporting-decision-tree page under breach reporting on this site is the cross-regime branching tree. This page is the CRA Article 14 walk only. A yes on Article 14 does not skip GDPR, NIS2, DORA, or any other regime.
- The signed-in CRA ladder tracks recorded awareness for findings the organisation classified as CRA-in-scope actively exploited vulnerabilities. That tracker does not start an Article 14 clock, does not decide that you are a manufacturer, does not walk this tree on YOUR incident, and does not file with a CSIRT or ENISA. A named human still files.
How to read this table
Walk top to bottom. A yes on an earlier row does not skip later rows that still apply. The two Article 14 tracks — actively exploited vulnerability and severe incident — can both be in play; they share the 24-hour early warning and the 72-hour notification and diverge at the final report. Last verified 9 September 2026. Not legal advice.
Each terminal cell names a live guide on this site, or names an unpublished dedicated rung guide in prose. This table is not YOUR determination. It does not start a clock.
- If yes and if no are decision logic distilled from the cited article. They are not an instruction to file.
- Kind of text labels the cited source as a legal requirement, Commission materials, or agency guidance. Do not treat guidance as the article.
- Clock-start is the event the cited limb names — the manufacturer becoming aware. Opening this page is not that event.
Decision tree — Article 14 walk
Work every row that might match. This is an accessible table, not a click-through widget. Last verified 9 September 2026 against Article 14 on EUR-Lex. Not legal advice. Not YOUR determination. Does not start a clock.
| Question | If yes | If no | Kind of text |
|---|---|---|---|
| Are you the manufacturer of a product with digital elements made available on the Union market — the responsible manufacturer for Article 14? | Continue. Article 14 is a manufacturer notification duty. Article 3(13): a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark. This table does not find that YOU are that person. The who-is-covered guide on this site is the economic-operator roles page. The CRA overview on this site is the pillar page. | Stop this tree for Article 14 manufacturer reporting. Importer, distributor, authorised representative, and open-source software steward are different roles. Article 14 does not become their duty because a product exists. The who-is-covered guide on this site is the economic-operator roles page. Other regimes may still apply. The reporting-decision-tree page under breach reporting on this site is the cross-regime branching tree. | Legal requirement — Articles 3(13) and 14. Only if the CRA applies. This page does not classify YOU. |
| Is it an actively exploited vulnerability contained in the product with digital elements that the manufacturer has become aware of? | Article 14(1) track. Continue to clock-start and rungs. Article 14(1): a manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7, and to ENISA, via the single reporting platform established pursuant to Article 16. Article 3(42): a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner. The CRA-cluster Article 14 overview on this site is the hub. The statute-clock Article 14 guide on this site is the ladder. A dedicated actively-exploited guide is not on this site yet. Naming it is not a link. This cell does not find that YOUR CVE is actively exploited. | Do not treat 'not actively exploited' as 'no Article 14 duty'. Continue to the severe-incident row. Do not invent a CVE catalogue, a KEV list, or a scanner match as the Article 14(1) test. | Legal requirement — Articles 3(42) and 14(1). This page does not score YOUR finding. |
| Is it a severe incident having an impact on the security of the product with digital elements that the manufacturer has become aware of? | Article 14(3) track. Continue to clock-start and rungs. Article 14(3): a manufacturer shall notify any severe incident having an impact on the security of the product with digital elements that it becomes aware of simultaneously to the same CSIRT and to ENISA, via the same platform. Article 14(5): an incident is severe where it negatively affects or is capable of negatively affecting the ability of the product to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions; or it has led or is capable of leading to the introduction or execution of malicious code in the product or in the network and information systems of a user of the product. The two tracks share the 24-hour and 72-hour marks and diverge at the final report. The CRA-cluster Article 14 overview on this site is the hub. The statute-clock Article 14 guide on this site is the ladder. | If neither the actively-exploited row nor this row is in play, this tree does not find an Article 14 manufacturer notification. Other regimes may still apply. The reporting-decision-tree page under breach reporting on this site is the cross-regime branching tree. The NIS2 incident-reporting guide on this site is Article 23. The DORA incident-reporting guide on this site is Articles 18–19. | Legal requirement — Articles 14(3) and 14(5). Qualitative. This page does not score YOUR incident. |
| Has the manufacturer become aware — has the Article 14 clock started? | Clock-start is the manufacturer becoming aware of the actively exploited vulnerability or the severe incident. Continue to which rung is due. This table does not find that minute in UTC. Counsel maps YOUR facts. The statute-clock Article 14 guide on this site is the ladder. The CRA-cluster Article 14 overview on this site is the hub. A KEV match, a scanner alert, a customer report, or recorded awareness in the signed-in ladder may be how you learn a fact. None of those events is, by itself, the legal finding that you have become aware. | Reading this page is not becoming aware. Walking this table does not start 24 hours, 72 hours, 14 days, or one month. Do not start a clock from opening the tree. If counsel later says awareness has occurred, return to which rung is due. The signed-in ladder, if you use it, tracks recorded awareness — it does not decide that minute and does not start an Article 14 clock. | Legal requirement — Articles 14(1), 14(2), 14(3) and 14(4) ('becomes aware'). Commission CRA materials on awareness are guidance, not the regulation. |
| Which rung is due — the 24-hour early warning? | Early warning: without undue delay and in any event within 24 hours of the manufacturer becoming aware. Article 14(2)(a) on the actively-exploited track; Article 14(4)(a) on the severe-incident track. Indicate, where applicable, the Member States on whose territory the manufacturer is aware the product has been made available. The statute-clock Article 14 guide on this site is the ladder. The CRA-cluster Article 14 overview on this site is the hub. A dedicated 24-hour early-warning guide is not on this site yet. Naming it is not a link. This cell does not start the 24 hours. | Continue to the 72-hour row. The 24-hour band and the 72-hour band are not averaged into one number. Missing the early-warning window does not skip the notification. | Legal requirement — Article 14(2)(a) or Article 14(4)(a). |
| Which rung is due — the 72-hour notification? | Notification: without undue delay and in any event within 72 hours of the manufacturer becoming aware — the same becoming-aware event as the 24-hour early warning, not a second, later start. Article 14(2)(b) on the actively-exploited track (vulnerability notification); Article 14(4)(b) on the severe-incident track (incident notification). The statute-clock Article 14 guide on this site is the ladder. The CRA-cluster Article 14 overview on this site is the hub. A dedicated 72-hour notification guide is not on this site yet. Naming it is not a link. This cell does not start the 72 hours. | Continue to the final-report row. Do not treat 72 hours as three days. Do not paste NIS2's 24/72/one-month ladder onto these marks. | Legal requirement — Article 14(2)(b) or Article 14(4)(b). |
| Which rung is due — the final report? | Two marks, not one number. Actively-exploited track — Article 14(2)(c): no later than 14 days after a corrective or mitigating measure is available (measure availability, not awareness). Severe-incident track — Article 14(4)(c): within one month after the submission of the incident notification under Article 14(4)(b) (submission of that 72-hour notification, not awareness, and not measure availability). The statute-clock Article 14 guide on this site is the ladder. The CRA-cluster Article 14 overview on this site is the hub. A dedicated final-report guide is not on this site yet. Naming it is not a link. This cell does not find that a measure is available and does not start 14 days or one month. | If no final-report mark is yet running, stay on the earlier rungs. Do not paste the 14-day actively-exploited mark onto the severe-incident one-month mark, or the reverse. | Legal requirement — Article 14(2)(c) or Article 14(4)(c). Those two final-report marks are not one number. |
| Where does the notification go? | Simultaneously to the CSIRT designated as coordinator and to ENISA, via the single reporting platform established pursuant to Article 16, using the electronic notification end-point of that CSIRT (Articles 14(1), 14(3), 14(7) and 16). The where-to-submit guide on this site is the Article 14 channel page. The ENISA-workflow guide on this site is the platform-flow page. The CSIRT guide on this site is the coordinator-interaction page. This table does not name YOUR CSIRT and does not run the Article 14(7) cascade. Article 14(8) user information is a different stream from the CSIRT/ENISA filings. | Do not invent a national email as the statutory desk, and do not treat a NIS2 Article 23 filing or a DORA Article 19 filing as the Article 14 notification. Filing one does not discharge the others. If this tree has not found an Article 14 manufacturer notification, stop this tree; other regimes may still apply. | Legal requirement — Articles 14(7) and 16. ENISA Single Reporting Platform pages are agency guidance, not the regulation. |
The two triggers, quoted — not YOUR finding
Article 14 has two mandatory tracks. They share a 24-hour early warning and a 72-hour notification. They diverge at the final report. This page does not invent a CVE list, a KEV list, or a severity score that the article does not state. Last verified 9 September 2026. Not legal advice.
| Trigger | What the text says | Kind of text | Last verified |
|---|---|---|---|
| Actively exploited vulnerability — Article 14(1) | A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator and to ENISA, via the single reporting platform established pursuant to Article 16. | Legal requirement — Article 14(1). Only if the CRA applies. | 9 September 2026 |
| Actively exploited vulnerability — definition | Article 3(42): a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner. | Legal requirement — Article 3(42). This page does not find that YOUR CVE is actively exploited. | 9 September 2026 |
| Severe incident — Article 14(3) | A manufacturer shall notify any severe incident having an impact on the security of the product with digital elements that it becomes aware of simultaneously to the same CSIRT and to ENISA, via the same platform. | Legal requirement — Article 14(3). | 9 September 2026 |
| Severe — Article 14(5) | An incident having an impact on the security of the product with digital elements shall be considered to be severe where it negatively affects or is capable of negatively affecting the ability of the product to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions; or it has led or is capable of leading to the introduction or execution of malicious code in the product or in the network and information systems of a user of the product. | Legal requirement — Article 14(5). Qualitative. This page does not score YOUR incident. | 9 September 2026 |
Legal requirement versus Commission and ENISA guidance
The table below labels each text. Do not treat guidance as the article, and do not treat the article as optional because a FAQ exists. Last verified 9 September 2026. Not legal advice.
| Text | What it is | What this page does not do |
|---|---|---|
| Regulation (EU) 2024/2847 Articles 3(13), 3(42), 14, 16 and 71(2) | Legal requirement — the regulation, only if it applies. | Does not apply those articles to YOU. Does not start a clock. Does not decide that you are a manufacturer. |
| European Commission CRA reporting page and Commission FAQs on CRA implementation | Commission materials. Guidance, not the regulation. | Does not treat a Commission FAQ as a substitute for Article 14, and does not treat Commission awareness language as starting YOUR clock. |
| ENISA Single Reporting Platform page and SRP FAQ | Agency guidance on the platform ENISA establishes under Article 16. Not the regulation. | Does not treat an ENISA FAQ as starting YOUR clock, and does not treat a named portal URL as proof the production system is live. |
What to do now
As of last verification on 9 September 2026, Article 14 applies from 11 September 2026 — two days from that verification date. The list below is operational preparation. It is not a determination that the CRA applies to YOU, that you are a manufacturer, or that a reporting clock has started. Walk it with counsel.
- Ask counsel whether YOU are a manufacturer of a product with digital elements made available on the Union market. This page does not run that test. The who-is-covered guide on this site is the roles page. Marking CRA in an obligation map is not that determination.
- If counsel says Article 14 may apply, walk the table above with counsel: actively exploited versus severe incident, awareness, which rung, where it goes. This tree does not start that clock.
- Open the statute-clock Article 14 guide on this site for the 24-hour / 72-hour / 14-day ladder. Open the CRA-cluster Article 14 overview on this site for how Article 14 sits in the cluster. Those two pages agree on the marks.
- Do not treat recorded awareness in the signed-in ladder as becoming aware. Do not treat a KEV listing as automatic becoming-aware. Do not paste NIS2's one-month final report onto CRA's 14-day actively-exploited final report.
- A dedicated 24-hour early-warning, 72-hour notification, final-report, and actively-exploited guide is not on this site yet. Naming them is not a link.
Checklist
This is a question list, not a filing, and not YOUR determination. Walk it with counsel. The statute-clock Article 14 guide on this site is the ladder. The CRA-cluster Article 14 overview on this site is the hub. The CRA overview on this site is the pillar page.
- Does the CRA apply? Manufacturer of a product with digital elements made available on the Union market. This page does not run that test.
- Actively exploited vulnerability under Article 3(42), or severe incident under Article 14(5)? Do not invent a CVE list as the test.
- Awareness (UTC): the minute you currently believe the manufacturer became aware, in Article 14's words. Do not treat reading this page as becoming aware. This page does not find that minute.
- Early warning: 24 hours from becoming aware — Article 14(2)(a) or 14(4)(a). Recipients: the CSIRT designated as coordinator and ENISA via the single reporting platform.
- Notification: 72 hours from becoming aware — Article 14(2)(b) or 14(4)(b). Same start event as the 24-hour early warning.
- Final report, actively-exploited track: 14 days after a corrective or mitigating measure is available — Article 14(2)(c). Not from awareness. Not the 24-hour mark.
- Final report, severe-incident track: one month after submission of the 72-hour incident notification — Article 14(4)(c). Not 14 days.
- Article 14 from 11 September 2026 (Article 71(2)). This page does not start that clock.
- The signed-in ladder, if you use it, tracks recorded awareness. It does not run this tree. It does not submit. A named human still files.
- Document the assessment, including a no-notification decision. This page does not keep YOUR file.
Where this shows up in ShipReady Metrics
The signed-in app does not run this tree on YOUR incident, does not decide that the CRA applies, does not decide that you are a manufacturer, does not decide that a finding is an actively exploited vulnerability or a severe incident, does not start an Article 14 clock, and does not file with a CSIRT or ENISA. None of the surfaces below is 'CRA applies', 'this clock has started', or an instruction to submit a filing.
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour / 72-hour / 14-day ladder from recorded awareness for findings the organisation classified as CRA-in-scope actively exploited vulnerabilities. That tracker is recorded awareness only. It does not start an Article 14 clock. It does not decide that you are a manufacturer. It does not walk this table. It does not file. A named human still files.
The obligation map lists frameworks the organisation has marked in-scope, including cra if that mark is set. That mark is not a determination that you are a manufacturer of a product with digital elements, and not a legal opinion. The cyber risk register lives under Security. None of those surfaces files an Article 14 early warning, notification, or final report with a CSIRT or ENISA.
This page does not document a public demo URL. There is no public CRA demo path.
Primary sources (last verified 9 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/2847 of 23 October 2024 (Cyber Resilience Act), Articles 3(13), 3(42), 14, 16 and 71(2), is a legal requirement only if it applies. Article 14 reporting applies from 11 September 2026 (Article 71(2)). The European Commission's CRA reporting page and CRA implementation FAQs are Commission materials, not the regulation. ENISA's Single Reporting Platform page and SRP FAQ are agency guidance on the Article 16 platform, not the regulation. Directive (EU) 2022/2555 Article 23 is a different instrument; the NIS2 incident-reporting guide is on this site. Regulation (EU) 2022/2554 Articles 18–19 are a different instrument; the DORA incident-reporting guide is on this site. These are not a complete world list. Not legal advice.
The statute-clock Article 14 guide on this site is the live ladder under breach reporting. The CRA-cluster Article 14 overview on this site is the Article 14 hub. The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page. The where-to-submit guide on this site is the Article 14 channel page. The ENISA-workflow guide on this site is the platform-flow page. The CSIRT guide on this site is the coordinator-interaction page. The reporting-decision-tree page under breach reporting on this site is the cross-regime branching tree. A dedicated 24-hour early-warning, 72-hour notification, final-report, and actively-exploited guide is not on this site yet. Naming them is not a link.