EU CRA Clause Article 14
Reporting obligations for actively exploited vulnerabilities and severe incidents
Regulation (EU) 2024/2847 (Cyber Resilience Act)
Article 14 of the EU Cyber Resilience Act sets the vulnerability and incident reporting duty that has applied since 11 September 2026. Manufacturers of products with digital elements must notify ENISA (routed to the relevant national CSIRT via the Single Reporting Platform) on a three-step timeline: an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident, and a substantive notification within 72 hours. The final report runs on two clocks: no later than 14 days after a corrective measure is available for an actively exploited vulnerability, but within one month for a severe incident. The 'becoming aware' trigger is wide, so the clock starts at first credible internal awareness. Manufacturers file once, into the Single Reporting Platform that ENISA established under Article 16 and switched on the same day the duty began; the receiving CSIRT then shares the notification with the CSIRTs of other Member States where the product is available. Open-source software stewards come under the parallel Article 24(3) reporting duty from 11 December 2027.
Where Forge applies this
Verified against the primary source. Standards are periodically revised — always confirm the current text.