Regulation (EU) 2024/2847
CRA Article 14 — the 24-hour, 72-hour and 14-day reporting clocks
“A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator … and to ENISA … (a) an early warning notification … within 24 hours of the manufacturer becoming aware of it; (b) … a vulnerability notification … within 72 hours …; (c) … a final report, no later than 14 days after a corrective or mitigating measure is available.”
Article 14 is the obligation already in force. It applies from 11 September 2026, more than a year ahead of the rest of the Regulation.
It creates a three-stage clock for any actively exploited vulnerability you become aware of: early warning within 24 hours, a fuller vulnerability notification within 72 hours, and a final report within 14 days of a fix or mitigation being available.
Notification is simultaneous to both the CSIRT designated as coordinator and ENISA, through the single reporting platform established under Article 16. The same structure applies to severe incidents affecting the security of the product under Article 14(3).
What it actually requires
- 24 hours — early warning
- Without undue delay and in any event within 24 hours of becoming aware. Must indicate, where applicable, the Member States where the product has been made available.
- 72 hours — vulnerability notification
- General information about the product, the general nature of the exploit and the vulnerability, corrective or mitigating measures taken and those users can take, plus how sensitive you consider the information.
- 14 days — final report
- No later than 14 days after a corrective or mitigating measure is available. Must describe the vulnerability including severity and impact, any known malicious actor exploiting it, and the security update or corrective measures made available.
- The trigger is awareness
- The clock starts when the manufacturer becomes aware of an ACTIVELY EXPLOITED vulnerability — not on disclosure, and not for vulnerabilities that are merely known.
Dates that apply
| Date | What applies |
|---|---|
| 11 September 2026 | Article 14 reporting obligations apply. This is the earliest CRA duty to bite. |
| 11 December 2027 | The remainder of the Regulation applies. |
The rest of the CRA
- CRA Annex I: the SBOM Requirement in Full
- CRA Article 13: Manufacturer Obligations Explained
- CRA Deadlines: Every Date That Applies
- EU Cyber Resilience Act — full compliance overview
Producing the Annex I SBOM and tracking which listed vulnerabilities actually affect your product is what O3 generates automatically, in CycloneDX or SPDX. Book a demo.