What CRA Article 14 actually requires
A plain reading of the reporting duty, what triggers it, and what a manufacturer needs in place to meet it.
Who this applies to
Manufacturers who place a product with digital elements on the EU market. Not just software vendors: a robot controller, a smart meter, an EV charger and an industrial gateway are all products with digital elements. If you put your name on it and sell it in the EU, the duty is yours, including where the software was written by a supplier.
What triggers the duty
Two separate triggers, each with its own clock:
| Trigger | What it means in practice |
|---|---|
| Actively exploited vulnerability | A vulnerability in your product with reliable evidence that someone has executed a malicious act against a user. Not a theoretical CVE in a dependency. Exploitation in the wild. |
| Severe incident | An incident affecting the security of the product that negatively impacts its ability to protect availability, authenticity, integrity or confidentiality. |
The three windows
| Deadline | What you file |
|---|---|
| 24 hours from becoming aware | Early warning to ENISA and your CSIRT, indicating whether exploitation appears malicious. A holding notification, not a full analysis. |
| 72 hours from becoming aware | Vulnerability notification: general information about the product, the nature of the vulnerability, corrective or mitigating measures taken and available to users. |
| 14 days after a corrective measure is available | Final report: description of the vulnerability, severity and impact, root cause where available, and the fix applied. |
Separately, users must be informed of the vulnerability and, where necessary, of corrective measures they can apply themselves.
Why 24 hours is the hard part
The clock starts when you become aware, not when you finish investigating. Meeting it requires three things to already exist on the day it happens:
- A maintained SBOM per product. You cannot assess whether a reported exploit touches your product if you do not know what is inside it. Reconstructing that during an incident is not possible in a day.
- Continuous monitoring against that SBOM. Awareness has to arrive from somewhere. In practice that means matched vulnerability feeds, not a customer email.
- A triage decision someone is authorised to make. Exploitable in your configuration, or not. Filed, or not. If that decision needs three meetings, the window is gone.
What happens on 11 December 2027
The rest of the regulation applies: essential cybersecurity requirements under Annex I Part I, the vulnerability handling requirements under Annex I Part II, technical documentation, conformity assessment and CE marking. Reporting is the first duty to bite, not the last.
Penalties
Non-compliance with the essential requirements or with the Article 13 and 14 obligations can attract administrative fines up to 15 million EUR or 2.5% of worldwide annual turnover, whichever is higher. Other breaches carry lower ceilings.
Not sure whether your products are in scope?
That is the free call. 45 minutes, no deck, and we will tell you if the answer is no.