← All tools
Free Tool

Article 14 Deadline Calculator

Enter the date and time you became aware of an actively exploited vulnerability or severe security incident. Get your exact Article 14 notification deadlines for ENISA reporting.

Last updated 29 August 2026

Key takeaways

  1. The Article 14 reporting clock starts when an organisation becomes aware of an actively exploited vulnerability or severe security incident.
  2. Active exploitation requires evidence of real attacks such as threat intelligence reports, customer incidents, honeypot detections, or observed exploit code.
  3. Notifications must be submitted to ENISA via the Single Reporting Platform, which shares submissions with the designated coordinating CSIRT.
  4. Persistent non-compliance with statutory notification deadlines can result in enforcement action from national market surveillance authorities.

The clock starts at the moment your organisation becomes aware — not when the reporter submitted.

+24hEarly WarningArt. 14(2)
Mon, 14 Sept 2026, 18:11 UTC
23h 59m remaining

Initial notification to ENISA / national CSIRT. Include: product name, brief description, evidence of exploitation.

+72hFull NotificationArt. 14(3)
Wed, 16 Sept 2026, 18:11 UTC
2d 23h remaining

Full notification with CVSS score, preliminary root cause, remediation timeline, and user notification plan.

+14 daysFinal ReportArt. 14(4)
Sun, 27 Sept 2026, 18:11 UTC
13d 23h remaining

Final report with confirmed root cause, completed mitigation, and lessons learned.

Note: Article 14 applies only when a vulnerability is actively exploited or constitutes a severe security incident. Non-exploited vulnerabilities follow your standard CVD process.

Frequently asked

When does the Article 14 clock start?+

The clock starts when your organisation becomes aware of the actively exploited vulnerability or severe security incident - not when the vulnerability was first reported to you by a researcher. Document the exact time you became aware internally.

What counts as 'actively exploited'?+

A vulnerability is actively exploited when evidence shows real attacks. Examples include threat intelligence reports, customer incident reports, honeypot detections, and exploit code observed in the wild. Proof-of-concept code alone does not typically qualify.

What if I miss a deadline?+

Notify ENISA as soon as possible and document why the delay occurred. The CRA does not specify per-incident penalties, but persistent non-compliance can lead to market surveillance action.

Do I notify ENISA directly?+

Notifications go to ENISA via the Single Reporting Platform (SRP), which makes them simultaneously available to your designated coordinating CSIRT. ENISA provides no submission API at this stage, so filing is a manual step you perform yourself. CVD Portal's Reporting plan produces an SRP-ready submission package for each stage and records what you filed and when.

Ready to automate your CVD programme?

CVD Portal integrates all these tools and handles your Article 13 and 14 obligations automatically.

Start your free portal →