Your RSA-2048 keys break in 2030. Find every one of them before attackers do.

Regulation (EU) 2024/2847

CRA Article 14 the 24-hour, 72-hour and 14-day reporting clocks

A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator … and to ENISA … (a) an early warning notification … within 24 hours of the manufacturer becoming aware of it; (b) … a vulnerability notification … within 72 hours …; (c) … a final report, no later than 14 days after a corrective or mitigating measure is available.
Article 14(1)-(2) · Read it on EUR-Lex

Article 14 is the obligation already in force. It applies from 11 September 2026, more than a year ahead of the rest of the Regulation.

It creates a three-stage clock for any actively exploited vulnerability you become aware of: early warning within 24 hours, a fuller vulnerability notification within 72 hours, and a final report within 14 days of a fix or mitigation being available.

Notification is simultaneous to both the CSIRT designated as coordinator and ENISA, through the single reporting platform established under Article 16. The same structure applies to severe incidents affecting the security of the product under Article 14(3).

What it actually requires

24 hours — early warning
Without undue delay and in any event within 24 hours of becoming aware. Must indicate, where applicable, the Member States where the product has been made available.
72 hours — vulnerability notification
General information about the product, the general nature of the exploit and the vulnerability, corrective or mitigating measures taken and those users can take, plus how sensitive you consider the information.
14 days — final report
No later than 14 days after a corrective or mitigating measure is available. Must describe the vulnerability including severity and impact, any known malicious actor exploiting it, and the security update or corrective measures made available.
The trigger is awareness
The clock starts when the manufacturer becomes aware of an ACTIVELY EXPLOITED vulnerability — not on disclosure, and not for vulnerabilities that are merely known.

Dates that apply

DateWhat applies
11 September 2026Article 14 reporting obligations apply. This is the earliest CRA duty to bite.
11 December 2027The remainder of the Regulation applies.

The rest of the CRA

Producing the Annex I SBOM and tracking which listed vulnerabilities actually affect your product is what O3 generates automatically, in CycloneDX or SPDX. Book a demo.

FAQ

Common
questions.

Everything teams ask before rolling this out. Still stuck? Reach our team.

  • Article 14(2)(a) of Regulation (EU) 2024/2847 requires a manufacturer to submit an early warning notification of an actively exploited vulnerability without undue delay and in any event within 24 hours of becoming aware of it, simultaneously to the CSIRT designated as coordinator and to ENISA via the single reporting platform.
  • The reporting obligations concerning actively exploited vulnerabilities and severe incidents apply from 11 September 2026, ahead of the rest of the Regulation, which applies from 11 December 2027.
  • Three stages: an early warning within 24 hours of becoming aware of an actively exploited vulnerability, a vulnerability notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure is available.
  • No. The reporting duty is triggered by ACTIVELY EXPLOITED vulnerabilities, and separately by severe incidents having an impact on the security of the product. A known but unexploited vulnerability does not start the clock, though it still falls under the Annex I vulnerability-handling requirements.