CRA Article 14: the 24-hour, 72-hour and 14-day reporting deadlines
Last updated: 2026-09-29
Article 14 of the Cyber Resilience Act has applied since 11 September 2026. A manufacturer that becomes aware of an actively exploited vulnerability in its product has three deadlines: an early warning within 24 hours, a vulnerability notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure is available. For a severe incident the first two deadlines are the same, and Article 14(4)(c) sets the final report within one month of the incident notification.
What the text says
The early warning, Article 14(2)(a):
"an early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available;"
The vulnerability notification, Article 14(2)(b), opens with:
"unless the relevant information has already been provided, a vulnerability notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the actively exploited vulnerability"
The final report, Article 14(2)(c), opens with:
"unless the relevant information has already been provided, a final report, no later than 14 days after a corrective or mitigating measure is available, including at least the following:"
The definition, Article 3, point (42):
"‘actively exploited vulnerability’ means a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner;"
Products already on the market, Article 69(3):
"By way of derogation from paragraph 2 of this Article, the obligations laid down in Article 14 shall apply to all products with digital elements that fall within the scope of this Regulation that have been placed on the market before 11 December 2027."
What this means in practice
- As written, the 24 hours and the 72 hours both run from the moment the manufacturer becomes aware. The 72 hours do not start at the early warning.
- The 14 days run from another moment: when a corrective or mitigating measure is available.
- The text counts in hours and days. It does not mention working days.
- The notification carries general information on the product, the exploit and the vulnerability, and on the measures taken or open to users. The final report adds the severity and impact, the malicious actor where known, and the security update or other corrective measures.
- Notifications go through the single reporting platform that ENISA runs (Article 14(7) and Article 16), to the CSIRT designated as coordinator in the Member State of the manufacturer's main establishment and, at the same time, to ENISA. A manufacturer with no main establishment in the Union follows the order in Article 14(7), third subparagraph.
- The platform has been live since 11 September 2026 at portal.cra-srp.enisa.europa.eu. ENISA's FAQ, updated on 17 September 2026, says that access needs an EU Login account with multi-factor authentication (FAQ 9) and that no API is provided at the initial release (FAQ 15).
- The same FAQ says that the platform's 72-hour counter currently shows a due time 48 hours after the early warning was submitted (FAQ 26). That due time can be earlier than the one Article 14(2)(b) gives.
- Article 14(8) also asks the manufacturer to inform the impacted users.
What to keep as evidence
- The moment of awareness: date, time and time zone, and the evidence of exploitation it rests on.
- The products and versions affected, and the Member States where they have been made available.
- For each notification: the time it was submitted, a copy, and the platform's reference.
- The date on which a corrective or mitigating measure became available.
- What users were told, and when.
Where DevKit Dossier fits
DevKit Dossier runs the Article 14 reporting clock for actively exploited vulnerabilities; severe incidents are outside it. When you mark a vulnerability in a release as actively exploited, it records the moment you became aware and shows when the 24-hour early warning and the 72-hour notification are due. The 14-day window opens once you record that a corrective or mitigating measure is available, and a checklist keeps each step with its time and reference. DevKit Dossier does not submit anything to ENISA's single reporting platform, gives no legal advice and does not certify anything; filing stays with you. It is hosted in the EU and self-serve, at a flat price per organisation of 49, 99 or 249 EUR per month with a 14-day trial.
Sources
- Regulation (EU) 2024/2847 (Cyber Resilience Act)
- ENISA, CRA Single Reporting Platform
- ENISA, press release of 11 September 2026 on the launch of the platform
- ENISA, Single Reporting Platform, frequently asked questions (updated 17 September 2026)
This guide is general information, not legal advice.
DevKit Dossier