DevKit Dossier

Cyber Resilience Act guides

CRA Article 14: the 24-hour, 72-hour and 14-day reporting deadlines

Last updated: 2026-09-29

Article 14 of the Cyber Resilience Act has applied since 11 September 2026. A manufacturer that becomes aware of an actively exploited vulnerability in its product has three deadlines: an early warning within 24 hours, a vulnerability notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure is available. For a severe incident the first two deadlines are the same, and Article 14(4)(c) sets the final report within one month of the incident notification.

What the text says

The early warning, Article 14(2)(a):

"an early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available;"

The vulnerability notification, Article 14(2)(b), opens with:

"unless the relevant information has already been provided, a vulnerability notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the actively exploited vulnerability"

The final report, Article 14(2)(c), opens with:

"unless the relevant information has already been provided, a final report, no later than 14 days after a corrective or mitigating measure is available, including at least the following:"

The definition, Article 3, point (42):

"‘actively exploited vulnerability’ means a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner;"

Products already on the market, Article 69(3):

"By way of derogation from paragraph 2 of this Article, the obligations laid down in Article 14 shall apply to all products with digital elements that fall within the scope of this Regulation that have been placed on the market before 11 December 2027."

What this means in practice

What to keep as evidence

Where DevKit Dossier fits

DevKit Dossier runs the Article 14 reporting clock for actively exploited vulnerabilities; severe incidents are outside it. When you mark a vulnerability in a release as actively exploited, it records the moment you became aware and shows when the 24-hour early warning and the 72-hour notification are due. The 14-day window opens once you record that a corrective or mitigating measure is available, and a checklist keeps each step with its time and reference. DevKit Dossier does not submit anything to ENISA's single reporting platform, gives no legal advice and does not certify anything; filing stays with you. It is hosted in the EU and self-serve, at a flat price per organisation of 49, 99 or 249 EUR per month with a 14-day trial.

Join the waitlist

Sources

This guide is general information, not legal advice.