CRA Article 14 Reportability Checker
Article 14 of Regulation (EU) 2024/2847 obliges manufacturers to report actively exploited vulnerabilities and severe security incidents to ENISA and designated CSIRTs within 24 hours. Vulnerabilities without active exploitation do not trigger statutory reporting.
Last updated 11 September 2026
Key takeaways
- Article 14 reporting applies exclusively to actively exploited vulnerabilities and severe security incidents affecting products with digital elements.
- Vulnerabilities that are exploitable but not actively exploited in the wild do not trigger statutory Article 14 notifications regardless of severity.
- Statutory reporting follows a three-stage cascade: a 24-hour early warning, a 72-hour full notification, and a final report.
- The final report deadline is 14 days after corrective measure availability for vulnerabilities, and one calendar month after the 72-hour notification for incidents.
Article 14 Reportability Triage
Answer three questions to determine whether your organisation must notify ENISA and your designated CSIRT under Regulation (EU) 2024/2847.
Per Commission guidance C(2026) 5252, active exploitation requires reliable evidence of actual attacks against users or systems. Proof-of-concept demonstrations and theoretical exploitability do not constitute active exploitation.
The Article 14 reporting clock starts when your organisation becomes aware of active exploitation or incident severity — not when the vulnerability was first reported.
Reportable under CRA Article 14
Article 14(2) mandates notification because this vulnerability is actively exploited in the wild. Under the CRA, severity does not restrict this obligation: any actively exploited vulnerability in a product with digital elements requires formal reporting to ENISA and the designated coordinating CSIRT. The 24-hour statutory clock started upon awareness.
Statutory Article 14 Deadlines
Computed from awareness date (Sat, 12 Sept 2026, 03:50 UTC)
| Stage | Statutory Rule | Deadline | Time Remaining |
|---|---|---|---|
| 24h Early Warning | Art. 14(2)(a) / 14(4)(a) — 24h from awareness | Sun, 13 Sept 2026, 03:50 UTC | 23h 59m remaining |
| 72h Full Notification | Art. 14(2)(b) / 14(4)(b) — 72h from awareness | Tue, 15 Sept 2026, 03:50 UTC | 2d 23h remaining |
| Final Report | Art. 14(2)(c) — 14 days after corrective measure available | Pending corrective measure | Runs once fix released |
Regulatory Reference: What Falls Outside Article 14
Where and How to Report
Notifications under Article 14 must be submitted simultaneously to ENISA and your designated national CSIRT coordinator via the Single Reporting Platform (SRP). CVD Portal prepares your compliant SRP submission packages but never transmits them automatically.
Notice:CVD Portal is not a notified body and cannot perform third-party conformity assessment. It does not provide legal advice. This tool provides regulatory triage based on Regulation (EU) 2024/2847 Article 14 and European Commission guidance C(2026) 5252. Where a manufacturer's product class or specific circumstances require qualified legal counsel or a notified body, consult designated specialists. This tool computes client-side in your browser and does not transmit notifications to any authority.
Frequently asked
Does every vulnerability require reporting under CRA Article 14?+
No. Article 14(1) reporting applies only when a vulnerability is actively exploited in the wild. A vulnerability that is exploitable but has not been used in real-world attacks does not trigger mandatory notification to ENISA or national CSIRTs, regardless of how high its CVSS severity score is. Non-exploited vulnerabilities are handled through standard coordinated vulnerability disclosure under Article 13.
What counts as active exploitation under Commission guidance C(2026) 5252?+
Active exploitation requires reliable evidence of actual attacks against users or systems in the wild. Proof-of-concept demonstrations, automated vulnerability scanner detections, and theoretical exploitability do not constitute active exploitation. Inclusions in trusted exploitation catalogues such as the CISA Known Exploited Vulnerabilities (KEV) catalogue or verified incident evidence confirm exploitation.
When does the 24-hour Article 14 reporting clock begin?+
The statutory reporting clock begins at the moment the manufacturer becomes aware that a vulnerability is actively exploited or that a severe incident has occurred. Awareness requires reasonable certainty following initial triage, not the arrival of an unverified report in a disclosure inbox. Once aware, the manufacturer must submit an early warning within 24 hours.
What is the difference between vulnerability and incident final reports?+
The final report deadlines differ by trigger. For an actively exploited vulnerability under Article 14(2)(c), the final report is due within 14 days after a corrective or mitigating measure is made available. For a severe security incident under Article 14(4)(c), the final report is due within one calendar month after the 72-hour notification. If both apply, the earlier deadline governs.
What criteria make a security incident severe under Article 14(5)?+
Under Article 14(5), an incident is severe if it negatively affects, or can negatively affect, the ability of the product to protect the availability, authenticity, integrity, or confidentiality of sensitive or important data or functions, or if it led, or is capable of leading, to the unauthorized introduction or execution of malicious code.
Other free CRA tools
Ready to automate your CVD programme?
CVD Portal integrates all these tools and handles your Article 13 and 14 obligations automatically.
Start your free portal →