Article 14 reporting under the Cyber Resilience Act applies from 11 September 2026. Manufacturers need to distinguish the two reportable event types and their different final-report clocks.
Two reporting paths and a shared start
The Cyber Resilience Act, Regulation (EU) 2024/2847, requires manufacturers to report certain events affecting products with digital elements. Its Article 14 reporting requirements apply from 11 September 2026. The Regulation generally applies from 11 December 2027, subject to its transitional provisions.
Article 14 has two reporting paths:
- an actively exploited vulnerability contained in a manufacturer's product with digital elements
- a severe incident affecting the security of that product
A vulnerability, CVE or suspected exploitation is not by itself necessarily a reportable actively exploited vulnerability. Equally, not every security incident meets the threshold for a severe incident. Each event must be assessed against the statutory thresholds and the facts available.
Both paths begin with the same two stages. Their final-report deadlines differ in both length and the event that starts the clock.
Early warning within 24 hours
For either reportable event, the manufacturer must provide an early warning without undue delay and in any event within 24 hours of awareness of the reportable event.
The 24-hour outer limit is not permission to wait. The purpose of the early warning is to begin the reporting process promptly once the manufacturer is aware of a reportable event.
Notification within 72 hours
The next notification is also due without undue delay and in any event within 72 hours of awareness of the reportable event.
This second stage follows the early warning. The statutory deadlines apply to both actively exploited vulnerabilities and severe incidents, but the Article 14 final-report requirements then diverge.
Final reports have different clocks
For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective or mitigating measure becomes available. This is not a deadline measured from awareness of the vulnerability.
For a severe incident, the final report must be submitted within one month after the 72-hour notification. This is a separate clock, tied to the earlier notification rather than to the availability of a corrective or mitigating measure.
| Reportable event | Early warning | Next notification | Final report |
|---|---|---|---|
| Actively exploited vulnerability | Without undue delay and in any event within 24 hours of awareness | Without undue delay and in any event within 72 hours of awareness | No later than 14 days after a corrective or mitigating measure is available |
| Severe incident | Without undue delay and in any event within 24 hours of awareness | Without undue delay and in any event within 72 hours of awareness | Within one month after the 72-hour notification |
For the first two stages, the outer limits are not permission to wait: each is due without undue delay and, in any event, by the stated deadline.
Reporting through the Single Reporting Platform
Manufacturers submit Article 14 notifications through ENISA's operational Single Reporting Platform and select the relevant CSIRT designated as coordinator. This is the statutory reporting route, not a direct report to ENISA alone.
Current platform terms describe access as role- and permission-based, using personal credentials. They require users to represent that they are authorised to act for their organisation. Those access arrangements do not by themselves establish legal authority, reportability or the validity of a notification.
A coordinator CSIRT may delay onward dissemination only under the bounded conditions in the Regulation and the applicable delegated regulation. Such delayed dissemination does not extend, or permit delay of, the manufacturer's Article 14 submission deadline.
What preparation should cover
Preparation is an operational matter, not a substitute for assessing the statutory thresholds. A proportionate process should cover:
- how potential events are assessed and when awareness of a reportable event is established
- named responsibilities for decisions and submission
- the information and evidence needed for each reporting stage
- secure access to the reporting platform and preservation of relevant evidence
These arrangements can help teams act promptly under pressure. They do not prove that an event is reportable or that a notification will meet the applicable legal requirements.
Conclusion
Article 14 uses a shared 24-hour and 72-hour start for two distinct reporting paths. The key difference is the final-report clock: 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability, and one month after the 72-hour notification for a severe incident.
Check current ENISA platform guidance and the European Commission's reporting guidance, as operational guidance may change. Assess each event against the statutory thresholds and its own facts.