Product Assurance Learning

Home / Guides

Guide

CRA Reporting Obligations: Article 14 Vulnerability Reporting

Since 11 September 2026, manufacturers of products with digital elements, including manufacturers outside the EU, must report actively exploited vulnerabilities and severe incidents under Article 14 of the Cyber Resilience Act. Reports go through the ENISA single reporting platform to a national CSIRT coordinator: an early warning within 24 hours, a notification within 72 hours and a final report later. The duty already covers products on the EU market today, including those placed before 11 December 2027.

8 min readUpdated 7 October 2026By the VeridEx editorial team

Who must report under the CRA, and for which products

The reporting obligations are set out in Article 14 of the Cyber Resilience Act (CRA), Regulation (EU) 2024/2847. They are addressed to the manufacturer of a product with digital elements. A manufacturer established outside the EU has the same duty as one established inside it.

The scope is wider than many exporters expect. Most CRA requirements apply only to units placed on the market from 11 December 2027. The reporting obligations are different. Under the transitional provisions in Article 69, they apply to all products in scope that are made available on the EU market. This includes products placed on the market before 11 December 2027.

In practice, this means the models you already sell in the EU are covered today. A controller shipped in 2024 and still in use by EU customers can trigger a report in 2026. For the overall calendar of the regulation, see our guide to Cyber Resilience Act dates.

Open-source software stewards also have reporting duties, but these currently apply only from 11 December 2027. This guide focuses on manufacturers.

What you must report: actively exploited vulnerabilities and severe incidents

Article 14 covers two kinds of events. They follow the same three-step logic but are defined differently.

Actively exploited vulnerabilities. The CRA defines these as vulnerabilities for which there is reliable evidence that a malicious actor has exploited them in a system without the permission of the system owner. A weakness found in your own testing, with no sign of exploitation, is not in this category. You still have to handle it under your vulnerability handling process.

Severe incidents having an impact on the security of the product. Under Article 14(5), an incident is severe where:

  • it negatively affects, or is capable of negatively affecting, the ability of the product to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions; or
  • it has led, or is capable of leading, to the introduction or execution of malicious code in the product or in the network and information systems of a user.

The classification depends on the facts of each case, so record your reasoning each time.

Article 15 also allows voluntary notifications, for example of vulnerabilities that are not actively exploited or of cyber threats. These are separate from the mandatory reports.

CRA reporting deadlines: 24 hours, 72 hours and the final report

The clock starts when the manufacturer becomes aware of the vulnerability or incident. Each step must be done without undue delay and in any event within the time limit below.

StepActively exploited vulnerability (Art. 14(2))Severe incident (Art. 14(4))
Early warningWithin 24 hours of becoming awareWithin 24 hours of becoming aware
NotificationWithin 72 hours of becoming awareWithin 72 hours of becoming aware
Final reportNo later than 14 days after a corrective or mitigating measure is availableWithin one month after the incident notification

The content grows at each step:

  • Early warning: where applicable, the Member States where you know the product has been made available. For incidents, also whether the incident is suspected of being caused by unlawful or malicious acts.
  • Notification: general information on the product, the nature of the exploit or incident, corrective or mitigating measures taken, measures users can take, and how sensitive you consider the information to be.
  • Final report: for vulnerabilities, a description with severity and impact, information on the malicious actor where available, and details of the security update or other corrective measure. For incidents, a detailed description, the likely threat type or root cause, and the mitigation measures applied and ongoing.

The coordinating authority can also ask for intermediate status updates. Implementing acts may further specify the format and procedure, so check the latest position.

Where to report: the CSIRT coordinator and the ENISA single reporting platform

Reports go to the CSIRT (Computer Security Incident Response Team) designated as coordinator, and simultaneously to ENISA, the EU cybersecurity agency. You do not send them separately. Under Article 14(7) and Article 16, you submit them through the single reporting platform run by ENISA, using the electronic end-point of the relevant CSIRT.

The relevant CSIRT is the one of the Member State of your main establishment in the EU. If you have no main establishment in the EU, Article 14(7) sets an order, based on the information available to you:

  1. the Member State where the authorised representative acting for you for the highest number of your products is established;
  2. otherwise, the Member State where the importer placing the highest number of your products on the market is established;
  3. otherwise, the Member State where the distributor making available the highest number of your products is established;
  4. otherwise, the Member State where the highest number of users of your products are located.

Work this out in advance and write it in your procedure, product family by product family if needed.

Platform status. ENISA announced on 11 September 2026 that the CRA Single Reporting Platform had been launched, and the Commission describes it as operational from that date. According to ENISA's published FAQ, access requires an EU Login account with multi-factor authentication, and the platform launched in English only. ENISA's platform documents use the term "assigned representative" for the individual user who submits notifications on behalf of a manufacturer. This is a platform role. It is a different thing from the authorised representative defined in the CRA. Check ENISA's pages for current access details before you need them.

Informing users of the product

Reporting to the authorities is only one part. Under Article 14(8), the manufacturer must also inform the impacted users, and where appropriate all users, of the vulnerability or incident. Where necessary, you must also tell them which risk mitigation and corrective measures they can deploy. Where appropriate, this should be in a structured, machine-readable format.

If you do not inform users in a timely manner, the notified CSIRTs may inform them directly when they consider it proportionate and necessary.

The role of the EU authorised representative and the importer

For non-EU manufacturers, the EU partner matters in three ways.

  • The obligation stays with the manufacturer. Article 14 is addressed to the manufacturer. Article 18(3) lists the minimum tasks of an authorised representative: keeping the EU declaration of conformity and technical documentation available, providing information on request and cooperating with authorities. Reporting is not on that list. You can agree support in the written mandate, but plan to meet the deadlines yourself.
  • The partner's location can decide your CSIRT. As shown above, the Member State of your authorised representative comes first in the order for manufacturers without an EU main establishment, followed by the importer.
  • Importers must pass information on. Under Article 19, an importer that becomes aware of a vulnerability in a product it has placed on the market must inform the manufacturer without undue delay. Agree how this reaches your on-call contact.

Our guide to the EU authorised representative explains the mandate and how to choose a partner.

Set up your CRA reporting process now

A 24-hour deadline leaves no time to design a process during an event. A practical setup covers these points:

  1. Contact point and owner. Name a person responsible for vulnerability handling and a deputy. Publish a single contact for vulnerability reports, such as a security email address or web form.
  2. Monitoring. Define the inputs: customer complaints, service staff, your EU partner, security researchers, your own logs and public advisories for the components you use.
  3. Triage. Write criteria to decide quickly whether a case is an actively exploited vulnerability, a severe incident, or neither. Record who decided, when, and why.
  4. Templates. Prepare drafts for the early warning, the notification and the final report, with the fields from Article 14 already listed. Keep a list of the Member States where each product is sold.
  5. Platform access. Register the people who will submit reports on the single reporting platform before you need it, and confirm which CSIRT is your coordinator.
  6. 24/7 on-call. The deadline runs on weekends and holidays. Set up an on-call rota so that someone can assess a case and submit an early warning within 24 hours at any time.
  7. User communication. Prepare advisory templates and distribution lists for customers and partners.
  8. Records and drills. Log each case with product, version, findings, decisions and dates. Run a test exercise at least once.

This sits next to your other after-sale duties under EU product law, such as handling complaints and corrective actions. The Cyber Resilience Act course covers vulnerability handling and the wider CRA requirements in more depth.

Penalties for missing CRA reporting obligations

Penalties for infringements of the CRA, including the reporting obligations, are laid down at national level by the Member States under Article 64. National authorities decide on penalties in individual cases. Check the national rules of the Member States where you sell.

According to the Commission's summary of the CRA, manufacturers that qualify as microenterprises or small enterprises may not be fined for failing to meet the 24-hour deadline for the early warning. This concerns fines for the 24-hour deadline only: the reporting obligations themselves still apply.

Key points

  • CRA reporting under Article 14 has applied since 11 September 2026, to EU and non-EU manufacturers alike.
  • It covers products already on the EU market, including units placed before 11 December 2027.
  • Actively exploited vulnerabilities and severe incidents need an early warning within 24 hours, a notification within 72 hours and a final report.
  • Reports go through the ENISA single reporting platform to the CSIRT coordinator, and users must be informed.
  • Your authorised representative's location can decide your CSIRT, but the reporting duty is yours.

To see how the CRA fits into the CE marking system as a whole, start with the free first module of CE Marking Fundamentals.

Learn the whole route, step by step

CE Marking Fundamentals takes you from the EU market rules to your first shipment, with templates and quizzes. Module 1 is free.

Frequently asked questions

Do CRA reporting obligations apply to products I sold before 2027?

Yes. Under Article 69 of the CRA, the reporting obligations apply to all products with digital elements in scope that are made available on the EU market, including those placed on the market before 11 December 2027. Models you already sell in the EU are covered since 11 September 2026.

How long do I have to report an actively exploited vulnerability under the CRA?

You must send an early warning within 24 hours of becoming aware of it and a vulnerability notification within 72 hours. The final report is due no later than 14 days after a corrective or mitigating measure is available. For severe incidents the final report is due within one month after the incident notification.

Can my EU authorised representative report on my behalf?

Article 14 places the obligation on the manufacturer, and reporting is not among the minimum tasks of an authorised representative in Article 18(3). You can agree support in the mandate, but plan to meet the deadlines yourself. Your representative's Member State can decide which CSIRT you report to if you have no main establishment in the EU.

Is the ENISA single reporting platform live?

ENISA announced the launch of the CRA Single Reporting Platform on 11 September 2026, and the Commission describes it as operational from that date. ENISA's FAQ states that access requires an EU Login account with multi-factor authentication. Check ENISA's pages for the current access details.

This guide is general training material, not legal advice. EU rules and standard citations change: check the latest texts in the Official Journal of the European Union before you decide.

Related guides

Be first in line

Join the waitlist for launch pricing and a free CE applicability checklist. We will only email you about VeridEx courses.