Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What does a CRA Article 14 incident report look like?

Last verified

This is an illustrative, fictional Article 14 actively-exploited-vulnerability walkthrough: awareness at T0, a 24-hour early warning, a 72-hour notification, remediation, and a 14-day final report. It is not a real incident, not legal advice, and does not start a clock.

CRA incident-reporting example, last verified 9 September 2026 against Regulation (EU) 2024/2847 Articles 3(42), 14, 16 and 71(2) on EUR-Lex, ENISA Single Reporting Platform glossary and FAQ (agency guidance, not the regulation), and the European Commission's CRA reporting page (Commission materials, not the regulation). The manufacturer, product, timestamps, Member States, and field text below are invented for illustration. They are not a real incident, not a filing, not a template of record, and not a substitute for counsel. This page does not start a clock.

This is an illustrative, fictional walkthrough, not YOUR incident

Audience: an engineering leader, CISO, or incident responder who wants to see Regulation (EU) 2024/2847 Article 14 executed end to end. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the CRA applies, that you are a manufacturer, that a product with digital elements has been made available on the Union market, that you have become aware, or that a filing is due.

The scenario is invented. Illustrative Firmware GmbH is not a real company. Illustrative Hub firmware 3.2 is not a real product. ILLUS-AEV-2026-001 is an invented label, not a CVE and not a production tracker number. No figure on this page is a live organisation figure. Last verified 9 September 2026. Not legal advice.

  • Statute versus guidance: Articles 3(42), 14, 16 and 71(2) are legal requirements only if they apply. ENISA Single Reporting Platform glossary, FAQ, and Assigned-Representative guidance are agency guidance, not the regulation. The Commission's CRA reporting page is Commission materials, not the regulation. Sample field labels taken from ENISA's glossary are guidance on the Article 16 platform, not extra statutory limbs.
  • The CRA overview on this site is the pillar page. The CRA-cluster Article 14 overview on this site is how Article 14 sits in the cluster. The statute-clock Article 14 guide on this site is the ladder under breach reporting. Those two Article 14 pages agree on the marks. This example does not invent a second set of clocks.
  • A dedicated 24-hour early-warning, 72-hour notification, final-report, actively-exploited, and reporting-decision-tree guide is not on this site yet. Naming them is not a link. Each step below names the live Article 14 guides that are on this site.
  • The signed-in CRA ladder tracks recorded awareness for findings the organisation classified as CRA-in-scope. In this walkthrough, any ladder timestamps are recorded awareness on illustrative data, not a live organisation figure. This page does not invent a production tracker number. That tracker does not start an Article 14 clock and does not file. A named human still submits.

The invented scenario — not a real incident

For illustration only, assume counsel has already said Article 14 may apply to this invented manufacturer of an invented product with digital elements made available on the Union market. This page does not run that test for YOU. The facts below are fictional. Last verified 9 September 2026. Not legal advice.

Invented scenario facts (illustrative; fictional; not YOUR incident; not a real incident; not legal advice)
Invented factWhat this walkthrough pretendsWhat this page does not do
ManufacturerIllustrative Firmware GmbH (fictional). Main establishment in the Union is invented as Germany, only so Article 14(7) has a place to point in the story.Does not classify YOU as a manufacturer. Does not run the Article 14(7) cascade. Does not name YOUR CSIRT.
ProductIllustrative Hub firmware 3.2, a fictional product with digital elements the story treats as made available in DE, FR and NL.Does not find that a named real product is a product with digital elements. A dedicated products-in-scope guide is not on this site yet. Naming it is not a link.
TriggerActively exploited vulnerability under Article 14(1), as Article 3(42) defines that term: a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner. Invented evidence: a customer report of unauthorised firmware-update commands, plus the manufacturer's own confirmation of that evidence. Internal label ILLUS-AEV-2026-001 is fictional.Does not find that YOUR CVE is actively exploited. Does not treat a KEV listing, a scanner alert, or a customer email as, by itself, the legal finding that you have become aware.
TrackThe actively-exploited track in Article 14(1) and 14(2). Not the severe-incident track in Article 14(3) and 14(4). The 14-day final-report mark is not the one-month mark.Does not score YOUR incident under Article 14(5). Does not paste this walkthrough onto a severe incident.
T0 — recorded awareness (invented)Tuesday 22 September 2026, 09:00 UTC. After Article 14 applies (11 September 2026, Article 71(2)). Invented recorded-awareness minute, not a live organisation figure.Does not start YOUR clock. Does not find that you have become aware. Reading this page is not becoming aware.

Timeline table — invented marks on the Article 14 ladder

The 24-hour early warning, the 72-hour notification, and the 14-day final report are three distinct marks. This page does not average them, does not round 72 hours to three days, and does not treat 14 days as the severe-incident final report. Clock-start is the event the cited limb names. Every invented timestamp is illustrative. Last verified 9 September 2026 against Article 14 on EUR-Lex. Not legal advice. This table does not start a clock. It is not YOUR incident.

  • Recipients of the early warning, notification, and final report: the CSIRT designated as coordinator and ENISA, via the single reporting platform (Articles 14(1), 14(7) and 16). The where-to-submit guide on this site is the Article 14 channel page. The ENISA-workflow guide on this site is the platform-flow page. The CSIRT guide on this site is the coordinator-interaction page. This page does not name YOUR CSIRT.
  • Article 14(6): the CSIRT designated as coordinator initially receiving the notification may request an intermediate report. This invented walkthrough does not include that request. A delay of dissemination under Article 16(2) does not pause manufacturer Article 14 duties.
  • Those two final-report marks are not one number. Article 14(2)(c) is 14 days after a corrective or mitigating measure is available (actively-exploited track). Article 14(4)(c) is within one month after the submission of the 72-hour incident notification (severe-incident track). This walkthrough is the first track only.
Illustrative, fictional Article 14 timeline (not YOUR incident; not a real incident; not legal advice)
StepInvented UTC mark (illustrative)What Article 14 saysLive Article 14 guide on this siteKind of text
T0 — awareness22 September 2026, 09:00 UTC. Invented recorded awareness. T0+0.Article 14(1): a manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of, simultaneously to the CSIRT designated as coordinator and to ENISA, via the single reporting platform. Becoming aware is the start for the 24-hour and 72-hour marks. This page does not find that minute for YOU.The CRA-cluster Article 14 overview on this site is the cluster hub. The statute-clock Article 14 guide on this site is the ladder under breach reporting. They agree. A dedicated actively-exploited and reporting-decision-tree guide is not on this site yet. Naming them is not a link.Legal requirement — Articles 14(1) and 3(42). Only if the CRA applies. The invented T0 is not YOUR clock.
24-hour early warning22 September 2026, 22:00 UTC. T0+13 hours. Inside the 24-hour band. Invented submission time.Article 14(2)(a): without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, an early warning notification, indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available.The CRA-cluster Article 14 overview on this site is the cluster hub. The statute-clock Article 14 guide on this site is the ladder. A dedicated 24-hour early-warning guide is not on this site yet. Naming it is not a link.Legal requirement — Article 14(2)(a). The 24-hour band is not averaged with the 72-hour band.
Inform impacted users (parallel, not a 24-hour count)22 September 2026, 20:00 UTC. After T0. Invented user notice. Not converted into 24 hours.Article 14(8): after becoming aware, the manufacturer shall inform the impacted users of the product, and where appropriate all users, of that vulnerability or incident and, where necessary, of risk-mitigation and corrective measures. Article 14(8) is a different stream from the CSIRT/ENISA filings.The CRA-cluster Article 14 overview on this site and the statute-clock Article 14 guide on this site both keep Article 14(8) distinct from the 24-hour, 72-hour, and 14-day counts. This page does not invent a hour count for user notice.Legal requirement — Article 14(8). Distinct from the single reporting platform filing.
72-hour notification24 September 2026, 18:00 UTC. T0+57 hours. Inside the 72-hour band. Same start event as the 24-hour early warning — not a second, later start. Invented submission time.Article 14(2)(b): unless the relevant information has already been provided, a vulnerability notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the actively exploited vulnerability, with general information as available about the product, the general nature of the exploit and of the vulnerability, corrective or mitigating measures taken, measures users can take, and, where applicable, how sensitive the manufacturer considers the notified information to be.The CRA-cluster Article 14 overview on this site is the cluster hub. The statute-clock Article 14 guide on this site is the ladder. A dedicated 72-hour notification guide is not on this site yet. Naming it is not a link.Legal requirement — Article 14(2)(b). The 24-hour band and the 72-hour band are not one number.
Remediation — measure available26 September 2026, 12:00 UTC. Invented moment a corrective or mitigating measure (Illustrative Hub firmware 3.2.1, fictional) is available. This is the start of the 14-day mark — not awareness, and not the 72-hour submission.Article 14(2)(c) clocks the final report from measure availability, not from T0. This page does not find that a measure is available for YOU.The CRA-cluster Article 14 overview on this site is the cluster hub. The statute-clock Article 14 guide on this site is the ladder. A dedicated final-report guide is not on this site yet. Naming it is not a link.Legal requirement — Article 14(2)(c) clock-start. The invented update is not a real patch.
14-day final report (actively-exploited track)6 October 2026, 10:00 UTC. Nine days and 22 hours after the invented measure-availability mark. Inside the 14-day band that ends 10 October 2026, 12:00 UTC. Invented submission time.Article 14(2)(c): unless the relevant information has already been provided, a final report, no later than 14 days after a corrective or mitigating measure is available, including at least a description of the vulnerability, including its severity and impact; where available, information concerning any malicious actor that has exploited or that is exploiting the vulnerability; and details about the security update or other corrective measures that have been made available to remedy the vulnerability.The CRA-cluster Article 14 overview on this site is the cluster hub. The statute-clock Article 14 guide on this site is the ladder. A dedicated final-report guide is not on this site yet. Naming it is not a link.Legal requirement — Article 14(2)(c). This 14-day mark is not the severe-incident one-month mark in Article 14(4)(c).

Sample field content — illustrative, not a template of record

The cells below invent what an Assigned Representative might type. They are not a template of record, not a filing, and not live ENISA portal button labels. ENISA's CRA SRP glossary (agency guidance, last verified 9 September 2026) lists fields such as notification type, title, summary, and manufacturer name, and marks which are required at the 24-hour, 72-hour, and final-report stages. That glossary is agency guidance, not the regulation. The statutory content still comes from Article 14(2). Last verified 9 September 2026. Not legal advice.

  • Do not paste these invented cells into the ENISA platform. They are not a template of record. Counsel maps YOUR facts onto Article 14(2).
  • ENISA's Assigned-Representative guidance (agency guidance, not the regulation) describes submitting an early warning, then updating through the 72-hour and final-report stages on the same notification. This page does not invent screenshots. The live platform UI was not treated as a source of field text.
Invented sample fields (illustrative; fictional; not a template of record; not YOUR filing; not legal advice)
Stage / fieldInvented sample (fictional)What the cited text asks forKind of text
Early warning — notification typeVulnerability (actively exploited). Fictional.ENISA SRP glossary: notification type distinguishes an actively exploited vulnerability from a severe incident. Article 14(1) is the statutory trigger used here.Glossary field: agency guidance, not the regulation. Trigger: legal requirement — Article 14(1).
Early warning — titleIllustrative Hub firmware 3.2 — unauthorised update-channel commands (fictional). ILLUS-AEV-2026-001 is an invented label, not a CVE.ENISA SRP glossary: a short human-readable name. Not a statutory title format.Agency guidance, not the regulation.
Early warning — summary and T0Illustrative Firmware GmbH (fictional) recorded awareness at 22 September 2026, 09:00 UTC of an actively exploited vulnerability in Illustrative Hub firmware 3.2. Invented recorded awareness, not a live organisation figure.Article 14(2)(a) clocks 24 hours from becoming aware. ENISA glossary treats summary as a required early-warning field (guidance).Clock: legal requirement — Article 14(2)(a). Field label: agency guidance.
Early warning — Member States where the product has been made availableDE, FR, NL (illustrative). Not a finding that a real product is on those markets.Article 14(2)(a): indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available.Legal requirement — Article 14(2)(a).
72-hour — product, exploit, vulnerabilityProduct: Illustrative Hub firmware 3.2 (fictional). General nature of the exploit: unauthenticated remote command injection on the firmware-update handshake (illustrative). General nature of the vulnerability: missing authentication on that update channel (illustrative).Article 14(2)(b): general information as available about the product with digital elements, the general nature of the exploit and of the vulnerability.Legal requirement — Article 14(2)(b).
72-hour — measures taken, measures users can take, sensitivityMeasures taken: published isolation guidance; update in development (illustrative). Measures users can take: isolate the hub from untrusted networks until the update is applied (illustrative). Sensitivity: manufacturer considers exploit mechanics sensitive until the update is available (illustrative).Article 14(2)(b): corrective or mitigating measures taken, measures users can take, and, where applicable, how sensitive the manufacturer considers the notified information to be.Legal requirement — Article 14(2)(b).
Final report — description, severity, impactDescription (illustrative): command injection on the firmware-update handshake, exploited without permission of the system owner. Severity and impact described qualitatively as integrity of installed firmware (illustrative). This page does not invent a CVSS as a finding on YOUR product.Article 14(2)(c)(i): a description of the vulnerability, including its severity and impact.Legal requirement — Article 14(2)(c)(i).
Final report — malicious actorUnknown. No attribution available in this invented file.Article 14(2)(c)(ii): where available, information concerning any malicious actor that has exploited or that is exploiting the vulnerability.Legal requirement — Article 14(2)(c)(ii). 'Where available' is in the article. This page does not invent an actor.
Final report — security update or other corrective measuresIllustrative Hub firmware 3.2.1 (fictional) made available 26 September 2026, 12:00 UTC. Invented measure-availability mark. Final report invented as submitted 6 October 2026, 10:00 UTC — inside 14 days of that mark.Article 14(2)(c)(iii): details about the security update or other corrective measures that have been made available to remedy the vulnerability. The 14-day mark runs from that availability, not from T0.Legal requirement — Article 14(2)(c)(iii).

The 14-day mark is not the severe-incident final report

This walkthrough is the actively-exploited track. The severe-incident track shares the 24-hour early warning and the 72-hour notification. It diverges at the final report. Last verified 9 September 2026 against Article 14(2)(c) and Article 14(4)(c) on EUR-Lex. Not legal advice.

  • Do not paste NIS2's one-month final report onto CRA's 14-day actively-exploited final report. Do not paste CRA's 14-day mark onto the severe-incident one-month final report. Those two CRA marks are not one number.
  • A dedicated reporting-decision-tree guide is not on this site yet. Naming it is not a link. The CRA-cluster Article 14 overview on this site and the statute-clock Article 14 guide on this site both keep the two tracks distinct.
Two Article 14 final-report marks (not one number; not YOUR clock; not legal advice)
TrackFinal-report limbClock startsKind of text
Actively exploited vulnerability — this walkthroughNo later than 14 days after a corrective or mitigating measure is available. Article 14(2)(c).Measure availability — not awareness, and not the 72-hour submission.Legal requirement — Article 14(2)(c).
Severe incident — not this walkthroughWithin one month after the submission of the incident notification under Article 14(4)(b). Article 14(4)(c).Submission of that 72-hour incident notification — not awareness, and not measure availability. This page does not convert 'one month' into a number of hours.Legal requirement — Article 14(4)(c). This one-month mark is not the 14-day mark.

What to do now

The list below is operational preparation. It is not a determination that the CRA applies to YOU, that you are a manufacturer, or that a reporting clock has started. It is not an instruction to copy the invented timeline. Walk it with counsel. Last verified 9 September 2026. Not legal advice.

  • Ask counsel whether YOU are a manufacturer of a product with digital elements made available on the Union market, and whether an actively exploited vulnerability or a severe incident is on the facts. This page does not run those tests. The who-is-covered guide on this site is the roles page. Marking CRA in an obligation map is not that determination.
  • If counsel says Article 14 may apply, open the statute-clock Article 14 guide on this site for the 24-hour / 72-hour / 14-day ladder, and the CRA-cluster Article 14 overview on this site for how that ladder sits in the cluster. Those two pages agree. This example does not start that clock and does not invent a second set of clocks.
  • Decide how the organisation will record the minute it becomes aware, in UTC, and the minute a corrective or mitigating measure is available. Do not treat reading this page as becoming aware. Do not paste ILLUS-AEV-2026-001 or these invented timestamps onto YOUR file.
  • Do not paste the 14-day actively-exploited final report onto the severe-incident one-month final report. Do not treat a KEV listing as automatic becoming-aware.
  • The where-to-submit guide on this site is the Article 14 channel page. The ENISA-workflow guide on this site is the platform-flow page. The CSIRT guide on this site is the coordinator-interaction page. A dedicated 24-hour early-warning, 72-hour notification, final-report, actively-exploited, and reporting-decision-tree guide is not on this site yet. Naming them is not a link.

Checklist

This is a question list, not a filing, and not YOUR notice. Walk it with counsel. The statute-clock Article 14 guide on this site is the ladder. The CRA-cluster Article 14 overview on this site is the cluster hub. The CRA overview on this site is the pillar page.

  • Does the CRA apply? Manufacturer of a product with digital elements made available on the Union market. This page does not run that test. The invented manufacturer is not YOU.
  • Actively exploited vulnerability under Article 3(42), or severe incident under Article 14(5)? This walkthrough is the first track only. Do not invent a CVE list as the test.
  • Awareness (UTC): the minute you currently believe the manufacturer became aware, in Article 14's words. Do not treat reading this page as becoming aware. The invented T0 is not YOUR minute.
  • Early warning: 24 hours from becoming aware — Article 14(2)(a). Recipients: the CSIRT designated as coordinator and ENISA via the single reporting platform. The live Article 14 guides on this site are the cluster overview and the statute-clock page.
  • Notification: 72 hours from becoming aware — Article 14(2)(b). Same start event as the 24-hour early warning.
  • Final report, actively-exploited track: 14 days after a corrective or mitigating measure is available — Article 14(2)(c). Not from awareness. Not the 24-hour mark. Not the severe-incident one-month mark.
  • Final report, severe-incident track: one month after submission of the 72-hour incident notification — Article 14(4)(c). Not 14 days. Not this walkthrough.
  • Article 14 from 11 September 2026 (Article 71(2)). This page does not start that clock.
  • Document the assessment, including a no-notification decision. This page does not keep YOUR file. These invented cells are not a template of record.

Where this shows up in ShipReady Metrics

The signed-in app does not decide that the CRA applies, does not decide that you are a manufacturer, does not decide that a finding is an actively exploited vulnerability or a severe incident, does not start an Article 14 clock, and does not submit to ENISA or a CSIRT. None of the surfaces below is 'CRA applies', 'this clock has started', or an instruction to submit a filing. This page does not invent a production tracker number.

If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organisation has classified as CRA-in-scope. That is one product tracker for the CRA actively-exploited ladder. In this walkthrough, those timestamps are recorded awareness on illustrative data, not a live organisation figure. The 24-hour / 72-hour clocks run from the organisation's recorded awareness — a human determination the platform must not backdate. A KEV match timestamp is disclosure, not the clock. It does not start an Article 14 clock. It is not a determination that the CRA applies. A named-reviewer draft on test or illustrative data is not a filing. A named human still submits.

The obligation map lists frameworks the organisation has marked in-scope, including CRA if that mark is set. That mark is not a determination that the CRA applies, not a determination that you are a manufacturer of a product with digital elements, and not a legal opinion. The cyber risk register lives under Security. The CRA starter control-set is an illustrative readiness mapping, a starter subset, not CE marking, and not customer-visible as a CRA determination. None of those surfaces files an Article 14 early warning, notification, or final report with a CSIRT or ENISA.

This page does not document a public demo URL. There is no public CRA demo path. ENISA's Single Reporting Platform is guidance on the Article 16 platform, not a submit button in this product.

Primary sources (last verified 9 September 2026)

Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.

Regulation (EU) 2024/2847 of 23 October 2024 (Cyber Resilience Act), Articles 3(42), 14, 16 and 71(2), fetched from EUR-Lex on 9 September 2026, is a legal requirement only if it applies. Article 14 reporting applies from 11 September 2026 (Article 71(2)). The European Commission's CRA reporting page is Commission materials, not the regulation. ENISA's Single Reporting Platform page, SRP FAQ, and SRP glossary are agency guidance on the Article 16 platform, not the regulation. Sample field labels follow that glossary as guidance; statutory content follows Article 14(2). These are not a complete world list. Not legal advice.

The statute-clock Article 14 guide on this site is the live ladder under breach reporting. The CRA-cluster Article 14 overview on this site is the cluster hub. The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page. The where-to-submit guide on this site is the Article 14 channel page. The ENISA-workflow guide on this site is the platform-flow page. The CSIRT guide on this site is the coordinator-interaction page. The coordinated-vulnerability-disclosure guide on this site is the Annex I Part II CVD page. The evidence-retention guide on this site is the technical-documentation keep page. The readiness-checklist guide on this site is the end-to-end CRA readiness page. A dedicated 24-hour early-warning, 72-hour notification, final-report, actively-exploited, and reporting-decision-tree guide is not on this site yet. Naming them is not a link.

Frequently asked questions