Regulation (EU) 2024/2847  ·  Article 14  ·  applies from 11 September 2026

What CRA Article 14 actually requires

A plain reading of the reporting duty, what triggers it, and what a manufacturer needs in place to meet it.

Who this applies to

Manufacturers who place a product with digital elements on the EU market. Not just software vendors: a robot controller, a smart meter, an EV charger and an industrial gateway are all products with digital elements. If you put your name on it and sell it in the EU, the duty is yours, including where the software was written by a supplier.

The point most people miss. Article 14 applies from 11 September 2026 to products already placed on the market, by express derogation from the general transitional rule. You cannot wait for the next product cycle. Devices you shipped in 2023 are in scope.

What triggers the duty

Two separate triggers, each with its own clock:

TriggerWhat it means in practice
Actively exploited vulnerability A vulnerability in your product with reliable evidence that someone has executed a malicious act against a user. Not a theoretical CVE in a dependency. Exploitation in the wild.
Severe incident An incident affecting the security of the product that negatively impacts its ability to protect availability, authenticity, integrity or confidentiality.

The three windows

24h
Early warning
72h
Notification
14d
Final report
DeadlineWhat you file
24 hours from becoming aware Early warning to ENISA and your CSIRT, indicating whether exploitation appears malicious. A holding notification, not a full analysis.
72 hours from becoming aware Vulnerability notification: general information about the product, the nature of the vulnerability, corrective or mitigating measures taken and available to users.
14 days after a corrective measure is available Final report: description of the vulnerability, severity and impact, root cause where available, and the fix applied.

Separately, users must be informed of the vulnerability and, where necessary, of corrective measures they can apply themselves.

Why 24 hours is the hard part

The clock starts when you become aware, not when you finish investigating. Meeting it requires three things to already exist on the day it happens:

What happens on 11 December 2027

The rest of the regulation applies: essential cybersecurity requirements under Annex I Part I, the vulnerability handling requirements under Annex I Part II, technical documentation, conformity assessment and CE marking. Reporting is the first duty to bite, not the last.

Penalties

Non-compliance with the essential requirements or with the Article 13 and 14 obligations can attract administrative fines up to 15 million EUR or 2.5% of worldwide annual turnover, whichever is higher. Other breaches carry lower ceilings.

This page is not legal advice. It is a plain reading of the regulation by an engineer, written to help you work out whether you have a problem. For a formal position on your specific products, talk to us or to counsel.

Not sure whether your products are in scope?

That is the free call. 45 minutes, no deck, and we will tell you if the answer is no.