← EU Cyber Resilience Act Certification

Module 6 of 8 · 40 min

Article 14: reporting actively exploited vulnerabilities and severe incidents

The two triggers, the 24-hour, 72-hour and final-report clocks, the CSIRT and ENISA recipients through the single reporting platform, and user notification duties.

Learning objectives

  • State the two Article 14 triggers and their Article 3 definitions
  • Run both reporting timelines: 24-hour early warning, 72-hour notification, 14-day (vulnerability) and one-month (incident) final reports
  • Name the recipients and the mechanism: the coordinator CSIRT and ENISA via the single reporting platform
  • Decide what a described event obliges the manufacturer to do, and by when
  • Distinguish Article 14 reporting from Annex I Part II disclosure and from voluntary Article 15 reporting

What triggers Article 14

Two events trigger mandatory reporting: an actively exploited vulnerability contained in the product, and a severe incident having an impact on the security of the product. Actively exploited means there is reliable evidence that a malicious actor has exploited the vulnerability in a system without the permission of its owner. A severe incident includes one that negatively affects or can negatively affect the product's ability to protect the availability, authenticity, integrity or confidentiality of data or functions. An internally discovered, unexploited bug is handled under Annex I Part II, not Article 14 — that boundary is a favourite exam discriminator.

The clocks

Both timelines start when the manufacturer becomes aware. For an actively exploited vulnerability: an early warning within 24 hours; a vulnerability notification within 72 hours with general information, an initial assessment, and any corrective or mitigating measures taken or available, including how sensitive the notified information is; and a final report no later than 14 days after a corrective or mitigating measure is available. For a severe incident: the same 24-hour early warning and a 72-hour incident notification, then a final report within one month after the incident notification. The clocks are cumulative stages of one obligation, not alternatives.

14 days runs from a corrective or mitigating measure becoming available (vulnerabilities); one month runs from the 72-hour incident notification (incidents). Swapping those two final-report anchors is the classic trap.

Who receives the report and how

Reports go simultaneously to the CSIRT designated as coordinator of the Member State where the manufacturer has its main establishment, and to ENISA. The main establishment is where cybersecurity-related decisions are predominantly taken, falling back to where the largest number of relevant employees sit; a manufacturer with no EU establishment reports to the CSIRT of the Member State where its products are most made available. Submission runs through the single reporting platform that ENISA operates under Article 16, with national electronic notification end-points. The obligations apply from 11 September 2026.

Users, voluntary reports, and consequences

After becoming aware of an actively exploited vulnerability or severe incident, the manufacturer must inform the impacted users, and where appropriate all users, without undue delay, about the event and where necessary about risk mitigations and corrective measures they can deploy — the CSIRT or ENISA can require it if the manufacturer fails to. Article 15 allows voluntary notification of other vulnerabilities, cyber threats and near misses, without creating new obligations for the notifier. Failing the Article 14 duties sits in the top penalty tier alongside Annex I breaches, reaching fifteen million euro or 2.5 percent of worldwide annual turnover.