Vulnerability reporting and incident reporting are separate obligations under the Cyber Resilience Act. Article 14 establishes two distinct reporting tracks with different triggers and statutory timelines.
Understanding this distinction is essential for building compliant internal escalation processes.
Reporting Obligation Effective Dates
Article 14 vulnerability and incident reporting becomes mandatory on 11 September 2026. This deadline applies to all products with digital elements made available on the EU market that remain in their supported lifetime.
Full product conformity, CE marking, and Annex I technical requirements apply from 11 December 2027. However, the reporting mechanism must be operational by September 2026.
The Two Reporting Tracks
1. Actively Exploited Vulnerabilities
A vulnerability triggers Article 14 reporting when evidence confirms active exploitation in the field. The legal trigger is confirmed malicious use, not CVSS score or internal severity.
The mandatory notification cascade follows this timeline:
- 24 hours: Early warning to the Single Reporting Platform, routing to ENISA and the national coordinator CSIRT.
- 72 hours: Detailed technical notification covering severity, affected versions, and user mitigations.
- 14 days after fix availability: Final report detailing root causes, security updates, and threat actor data.
The 24-hour clock begins the moment the manufacturer becomes aware of active exploitation.
2. Severe Incidents
A severe incident involves an event that impacts the security or functionality of a product. The notification timeline requires:
- 24 hours: Early warning notification.
- 72 hours: Detailed incident notification.
- One month after notification: Final report covering root cause analysis and corrective actions.
Products in Scope
Article 14 applies to all manufacturers of products with digital elements sold in the EU. This includes connected consumer hardware, industrial automation controllers, networking equipment, embedded firmware, and standalone security software.
Importers and distributors carry secondary responsibilities if an overseas manufacturer fails to report.
Single Reporting Platform Routing
The CRA establishes the Single Reporting Platform (SRP) operated by ENISA. Manufacturers submit notifications through one portal.
The system automatically routes the report to ENISA and the designated coordinating CSIRT in the manufacturer's home Member State. Manufacturers should register accounts and test credentials well before September 2026.
Essential Internal Processes
To meet statutory deadlines, manufacturers must establish four operational capabilities:
Detection and escalation routes. Teams must aggregate signals from disclosure portals, threat feeds, customer support, and CSIRT advisories. Escalation to decision-makers must occur within hours of initial detection.
Standing triage authority. Designated technical leaders must hold documented authority to file 24-hour early warnings without requiring executive or legal approval.
Pre-formatted notification templates. Teams must maintain pre-drafted templates aligned with SRP data fields to prevent delays during active incidents.
Immutable audit trails. Every report, triage assessment, and authority filing must be logged with verified timestamps for regulatory review.
Summary
Article 14 compliance requires operational readiness before 11 September 2026. Setting up monitored intake, clear triage authority, and tested reporting workflows ensures compliance.
The SME Readiness Gap
Larger organisations with established PSIRTs and threat intelligence programmes already have most of these capabilities in some form. For the majority of SMEs manufacturing hardware or software for the EU market, none of them exist today.
Building compliant detection, escalation, triage, reporting, and disclosure processes from scratch in the months remaining before September 2026 is achievable. It requires deliberate prioritisation and, for most SMEs, tooling that reduces the engineering burden.
CVD Portal provides the intake, triage, reporting, and audit trail infrastructure required for Article 14 compliance as a service. Manufacturers can be operationally ready with a functioning VDP, structured escalation workflow, pre-built report templates aligned to ENISA’s notification format, and full audit trail without building any of it in-house.
A Deeper Look at Each Obligation
This guide is the single-page overview. Each part of the reporting regime is covered in depth in our six-part series:
- When vulnerability and incident reporting become mandatory under the CRA
- Which vulnerabilities and incidents must be reported, and which do not
- How reporting to ENISA and national authorities is organised
- Understanding reporting timelines and follow-up obligations
- Preparing internal detection, escalation, and decision-making processes
- Linking vulnerability reporting to broader product and risk management
The Bottom Line
Vulnerability and incident reporting under the CRA are two distinct obligations with overlapping timelines, separate triggers, and different final report deadlines. Both become enforceable on 11 September 2026, on every product with digital elements in the EU market. The internal processes required to meet those timelines must be in place and tested before that date, not planned for after it.