Article 14, in plain language

Article 14 of the Cyber Resilience Act creates two reporting duties for manufacturers: one for vulnerabilities in your product that are being actively exploited, and one for severe incidents affecting your product’s security. Both run on the same first two clocks and diverge at the third.

Who this applies to

Any manufacturer placing a product with digital elements on the EU market, wherever the company is headquartered.Art. 2⁠(1)⁠ That covers installed software, firmware, connected devices, libraries and SDKs, and mobile apps. A purely hosted service is generally outside it, unless it is the remote data processing part of a product you place on the market.

Products already on the market stay in scope for reporting while they remain within their support period.Art. 69⁠(3)⁠ There is no exemption for older products.

The three clocks

All of them start from the moment you become aware, except the last, which is the detail most often got wrong.

Early warning, 24 hours

Within 24 hours of becoming aware.Art. 14⁠(2)⁠⁠(a)⁠ Deliberately short: for a vulnerability, the member states where you know the product is available. For a severe incident it is instead whether the incident is suspected of being caused by unlawful or malicious acts.Art. 14⁠(4)⁠⁠(a)⁠ It exists to tell the authority something is happening, not to be complete. Twenty-four hours includes nights and weekends.

Notification, 72 hours

Within 72 hours.Art. 14⁠(2)⁠⁠(b)⁠ The nature of the exploit, an initial assessment of severity and impact, corrective or mitigating measures you have taken, and what users can do themselves.

Final report

For a vulnerability: within 14 days of a corrective or mitigating measure becoming available.Art. 14⁠(2)⁠⁠(c)⁠ Note that this clock starts when the fix exists, not when you became aware, so a case can sit between the 72-hour notification and the start of this clock for a long time.

For an incident: within one month of submitting the incident notification.Art. 14⁠(4)⁠⁠(c)⁠ That runs from when you actually submitted it, not from the 72-hour deadline, which makes the recorded submission time worth keeping carefully.

Who receives it

The CSIRT designated as coordinator, and ENISA, through the single reporting platform.Art. 14⁠(7)⁠ If you are established in the EU, that is your member state of main establishment. If you are not, it is the member state where you have your most significant connection: your authorised representative, failing that your importer, then your distributor, then wherever most of your users are.

You must also inform affected users without undue delay, including what they can do about it.Art. 14⁠(8)⁠

The distinction that matters

The duty is triggered by an actively exploited vulnerability in your product. A dependency of yours appearing in a catalogue of exploited vulnerabilities is a strong reason to check, and it is not by itself a reportable event. Conflating the two produces either false alarms or filings you did not owe, and both are expensive.

Not sure whether this applies to you?

This produces evidence, timelines and drafts. It is not legal advice, and you remain the party responsible for reporting.