Most of the Cyber Resilience Act waits until 11 December 2027. Article 14 does not. Since 11 September 2026, a manufacturer that learns its product is being actively exploited has 24 hours to say so. The duty covers every product with digital elements on the EU market, including units sold years before the CRA existed.

For most manufacturers it is the first CRA obligation that can actually be missed. The deadline is counted in hours.

Who has to report

The manufacturer. That includes manufacturers outside the EU, and anyone who becomes a manufacturer under the CRA: an importer or distributor that sells the product under its own name, or a company that substantially modifies a product already on the market (Articles 21 and 22).

The class of the product does not matter. A default-class smart plug is covered just like a router. Products under their own sector rules are not: type-approved vehicles, medical devices, certified aviation products and marine equipment. Open-source software stewards report only from 11 December 2027.

One point of relief: according to the Commission's guidance, exploitation you already knew about before 11 September 2026 does not have to be reported. If you learn of it after that date, the duty applies, even for an old vulnerability.

Only two events start the clock

An actively exploited vulnerability. There is reliable evidence that a malicious actor has exploited a vulnerability in your product without the owner's permission (Article 3(42)). A proof of concept, a pentest finding or a researcher's private report is not enough. Those go through your normal vulnerability handling.

A severe incident affecting the security of the product. The incident harms, or can harm, the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions. Or it has led, or can lead, to malicious code being introduced or executed in the product or in users' systems (Article 14(5)). A breached build server that ships a tampered update is the textbook case. So is a leaked update-signing key.

Third-party components. A vulnerability in a library you ship becomes your reporting duty when it is contained in your product and actively exploited in your product. If the vulnerable function cannot be reached in your product, or there is no sign of exploitation in it, there is no mandatory report for you. The Commission's guidance of July 2026 says so explicitly. To rely on it, record three facts: is the affected version present, is the vulnerable function reachable, is there any sign of exploitation. A VEX statement in your vulnerability records is the natural place for this. Either way, tell the component's maintainer (Article 13(6)).

When the clock starts

The 24 hours run from the moment you become aware. According to the Commission's guidance, that is when a prompt initial assessment gives you a reasonable degree of certainty that one of the two events has happened. Proof is not required, and the clock waits neither for a meeting nor for a slow assessment.

Write the time down, with the name of the person who decided. The early warning asks for it.

Three reports, two clocks

StageActively exploited vulnerabilitySevere incident
Early warningWithin 24 hours of awareness. Name the Member States where the product is available, if known.Within 24 hours of awareness. Say whether unlawful or malicious action is suspected.
NotificationWithin 72 hours: the product, the nature of the exploit and the vulnerability, measures taken, measures users can take, how sensitive the information is.Within 72 hours: nature of the incident, initial assessment, measures taken, measures users can take, sensitivity.
Final reportNo later than 14 days after a fix or mitigation is available: description, severity, impact, threat actor if known, the fix.Within one month after the notification: description, severity, impact, likely root cause, mitigations.

The coordinating CSIRT may also ask for an intermediate report. Reporting is progressive: the early warning will almost always rest on an incomplete investigation. Send what you know, mark what is unconfirmed, and complete it in the next stage.

Where the reports go

Every report goes through ENISA's Single Reporting Platform. One submission reaches your coordinating CSIRT and ENISA at the same time (Articles 14(1) and 16). A few facts that matter on the day:

  • Access is by personal EU Login account with multi-factor authentication. Create the accounts now, for at least two people.
  • The platform works in English only. Prepare your templates in English.
  • You choose the coordinating CSIRT yourself, and ENISA warns that a wrong choice can invalidate the notification. It is the Member State where decisions on your products' cybersecurity are mainly taken. Without an EU establishment, the order is: where your authorised representative is, then your importer, then your distributor, then where most of your users are (Article 14(7)).
  • Drafts saved in the platform are visible only to the person who wrote them. Keep the master copy in your own case file, so a colleague can take over during the night.
  • Do not rely on the platform's countdown. At launch, the 72-hour counter ran from the time you submitted the early warning, not from awareness, and there is no counter for the 14-day final report. ENISA states that the counters do not replace the legal deadlines. Run your own clock.

Telling your users

Article 14(8) requires you to inform affected users, and where appropriate all users, without undue delay: what happened, and the mitigations or corrective measures they can apply. Use a structured, machine-readable format where you can; CSAF 2.0 is the format most integrators already process automatically. If you do not act in time, the CSIRT may inform them itself.

What a missed report costs

Breaching Article 14 can lead to fines of up to EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher (Article 64(2)). Micro and small enterprises are not fined for missing the 24-hour early warning, but they are for the 72-hour notification and the final report (Article 64(10)). Notifying does not by itself increase your liability (Article 17(4)).

When a case sits on the line, decide, write down why, and report if in doubt.

What to set up this week

  1. One decision owner and a deputy, by name. The decision to report belongs to one person.
  2. Two EU Login accounts with multi-factor authentication, for the people who will file.
  3. Your coordinating CSIRT, chosen with the Article 14(7) order and written down with the reason.
  4. Three templates in English: early warning, notification, final report. Fill in everything that does not change, such as your legal name and product list.
  5. An on-call rota. The 24 hours run on weekends too.
  6. One rehearsal. Take a realistic scenario, for example a library in your firmware appearing in a known-exploited list on a Friday evening, and time how long it takes to reach a drafted early warning.

For a company of twenty people, this is an afternoon's work.

This article explains Regulation (EU) 2024/2847 in plain words. It is not legal advice.