← All tools
Free Tool

CRA Article 14 Reportability Checker

Article 14 of Regulation (EU) 2024/2847 obliges manufacturers to report actively exploited vulnerabilities and severe security incidents to ENISA and designated CSIRTs within 24 hours. Vulnerabilities without active exploitation do not trigger statutory reporting.

Last updated 11 September 2026

Key takeaways

  1. Article 14 reporting applies exclusively to actively exploited vulnerabilities and severe security incidents affecting products with digital elements.
  2. Vulnerabilities that are exploitable but not actively exploited in the wild do not trigger statutory Article 14 notifications regardless of severity.
  3. Statutory reporting follows a three-stage cascade: a 24-hour early warning, a 72-hour full notification, and a final report.
  4. The final report deadline is 14 days after corrective measure availability for vulnerabilities, and one calendar month after the 72-hour notification for incidents.

Article 14 Reportability Triage

Answer three questions to determine whether your organisation must notify ENISA and your designated CSIRT under Regulation (EU) 2024/2847.

Per Commission guidance C(2026) 5252, active exploitation requires reliable evidence of actual attacks against users or systems. Proof-of-concept demonstrations and theoretical exploitability do not constitute active exploitation.

The Article 14 reporting clock starts when your organisation becomes aware of active exploitation or incident severity — not when the vulnerability was first reported.

Action RequiredRegulation (EU) 2024/2847 · Article 14

Reportable under CRA Article 14

Next Immediate Deadline
23h 59m remaining
24h early warning

Article 14(2) mandates notification because this vulnerability is actively exploited in the wild. Under the CRA, severity does not restrict this obligation: any actively exploited vulnerability in a product with digital elements requires formal reporting to ENISA and the designated coordinating CSIRT. The 24-hour statutory clock started upon awareness.

Statutory Article 14 Deadlines

Computed from awareness date (Sat, 12 Sept 2026, 03:50 UTC)

StageStatutory RuleDeadlineTime Remaining
24h Early WarningArt. 14(2)(a) / 14(4)(a) — 24h from awarenessSun, 13 Sept 2026, 03:50 UTC23h 59m remaining
72h Full NotificationArt. 14(2)(b) / 14(4)(b) — 72h from awarenessTue, 15 Sept 2026, 03:50 UTC2d 23h remaining
Final ReportArt. 14(2)(c) — 14 days after corrective measure availablePending corrective measureRuns once fix released

Regulatory Reference: What Falls Outside Article 14

Unexploited vulnerabilities:A vulnerability that is merely exploitable, however severe its CVSS score, does not start the 24-hour clock. Evidence of real attacks in the wild is the legal trigger.
Standard CVD inbox reports:Routine vulnerability reports from security researchers require intake, acknowledgment, and remediation under Article 13, but do not require notification to ENISA.
Non-severe incidents:Incidents that do not affect the availability, authenticity, integrity, or confidentiality of sensitive functions or lead to malicious code execution are not reportable under Article 14(5).
Unreachable third-party code:Per C(2026) 5252, a vulnerability in an integrated component is reportable only if the vulnerable functionality is reachable and actively exploited in your product.

Where and How to Report

Notifications under Article 14 must be submitted simultaneously to ENISA and your designated national CSIRT coordinator via the Single Reporting Platform (SRP). CVD Portal prepares your compliant SRP submission packages but never transmits them automatically.

Notice:CVD Portal is not a notified body and cannot perform third-party conformity assessment. It does not provide legal advice. This tool provides regulatory triage based on Regulation (EU) 2024/2847 Article 14 and European Commission guidance C(2026) 5252. Where a manufacturer's product class or specific circumstances require qualified legal counsel or a notified body, consult designated specialists. This tool computes client-side in your browser and does not transmit notifications to any authority.

Frequently asked

Does every vulnerability require reporting under CRA Article 14?+

No. Article 14(1) reporting applies only when a vulnerability is actively exploited in the wild. A vulnerability that is exploitable but has not been used in real-world attacks does not trigger mandatory notification to ENISA or national CSIRTs, regardless of how high its CVSS severity score is. Non-exploited vulnerabilities are handled through standard coordinated vulnerability disclosure under Article 13.

What counts as active exploitation under Commission guidance C(2026) 5252?+

Active exploitation requires reliable evidence of actual attacks against users or systems in the wild. Proof-of-concept demonstrations, automated vulnerability scanner detections, and theoretical exploitability do not constitute active exploitation. Inclusions in trusted exploitation catalogues such as the CISA Known Exploited Vulnerabilities (KEV) catalogue or verified incident evidence confirm exploitation.

When does the 24-hour Article 14 reporting clock begin?+

The statutory reporting clock begins at the moment the manufacturer becomes aware that a vulnerability is actively exploited or that a severe incident has occurred. Awareness requires reasonable certainty following initial triage, not the arrival of an unverified report in a disclosure inbox. Once aware, the manufacturer must submit an early warning within 24 hours.

What is the difference between vulnerability and incident final reports?+

The final report deadlines differ by trigger. For an actively exploited vulnerability under Article 14(2)(c), the final report is due within 14 days after a corrective or mitigating measure is made available. For a severe security incident under Article 14(4)(c), the final report is due within one calendar month after the 72-hour notification. If both apply, the earlier deadline governs.

What criteria make a security incident severe under Article 14(5)?+

Under Article 14(5), an incident is severe if it negatively affects, or can negatively affect, the ability of the product to protect the availability, authenticity, integrity, or confidentiality of sensitive or important data or functions, or if it led, or is capable of leading, to the unauthorized introduction or execution of malicious code.

Ready to automate your CVD programme?

CVD Portal integrates all these tools and handles your Article 13 and 14 obligations automatically.

Start your free portal →