ActLume blog
Practical guidance for CRA Article 14 reporting.
Understand manufacturer readiness, incident coordination, deadlines, staged reports, and the human-controlled ENISA SRP handoff.
Published articles
50 available
-
What must a manufacturer report under CRA Article 14, and when is each stage due?
CRA Article 14: the 24h, 72h and final-report sequence
Both Article 14 tracks start with 24-hour and 72-hour stages, but their final-report clocks start from different events.
Editorial date -
When does the CRA Article 14 reporting clock start for a manufacturer?
When does the CRA Article 14 clock start?
The 24-hour and 72-hour windows run from manufacturer awareness of an actively exploited vulnerability or a severe product-security incident.
Editorial date -
What makes a vulnerability actively exploited for CRA Article 14 reporting?
What is an actively exploited vulnerability under the CRA?
An actively exploited vulnerability requires reliable evidence that a malicious actor exploited a vulnerability without the system owner's permission.
Editorial date -
How should a manufacturer test whether an incident is severe under CRA Article 14?
How does the CRA define a severe product-security incident?
Article 14 treats an incident as severe when it meets either of two product-security impact tests concerning protected data, functions, or malicious code.
Editorial date -
What should a manufacturer prepare for the CRA Article 14 24-hour early warning?
What belongs in a CRA 24-hour early warning?
The first Article 14 stage is an early warning due without undue delay and within 24 hours of awareness, not a finished investigation report.
Editorial date -
What information belongs in the CRA 72-hour vulnerability notification?
Building the CRA 72-hour vulnerability notification
The 72-hour vulnerability stage adds available product, exploit, vulnerability, mitigation, user-action, and sensitivity information.
Editorial date -
What should a manufacturer prepare for the CRA 72-hour severe-incident notification?
Building the CRA 72-hour severe-incident notification
The 72-hour incident stage carries available general information, an initial assessment, and corrective or mitigating measures.
Editorial date -
What starts the CRA deadline for an actively exploited vulnerability final report?
When is the CRA vulnerability final report due?
The final report for an actively exploited vulnerability is due no later than 14 days after a corrective or mitigating measure becomes available.
Editorial date -
What starts the CRA final-report deadline for a severe product-security incident?
When is the CRA severe-incident final report due?
The final report for a severe incident is due within one month after the 72-hour incident notification.
Editorial date -
Why should a manufacturer assess the two CRA Article 14 reporting tracks separately?
The CRA has two Article 14 reporting tracks
Article 14 separately covers actively exploited vulnerabilities and severe incidents affecting product security, with distinct final-report rules.
Editorial date -
What should a manufacturer do when facts are incomplete at the CRA 24-hour reporting stage?
What if CRA facts are incomplete at 24 hours?
The CRA early warning comes before the fuller 72-hour notification, so teams need a controlled way to report known facts and preserve uncertainty.
Editorial date -
How should a manufacturer maintain evidence across the stages of a CRA Article 14 report?
Keep one evidence trail across CRA reporting stages
CRA notifications develop across the 24-hour, 72-hour, and final stages, making a traceable record of additions and corrections essential.
Editorial date -
How should a manufacturer record the awareness timestamp that starts CRA Article 14 deadlines?
How to record the CRA awareness timestamp
CRA reporting windows run from manufacturer awareness, so the case record should distinguish signal receipt, assessment, and the trigger decision.
Editorial date -
How should a manufacturer design an after-hours escalation chain for CRA Article 14 reporting?
Build a CRA escalation chain that works after hours
CRA early warnings and notifications use hour-based deadlines from awareness, so reporting ownership needs tested backups outside normal schedules.
Editorial date -
How should a manufacturer document a decision that a product-security case is not reportable under CRA Article 14?
How to document a CRA decision not to report
A non-report decision should show how the evidence was tested separately against the CRA definitions for active exploitation and severe incidents.
Editorial date -
How does the CRA Single Reporting Platform route a manufacturer's Article 14 notification?
How the CRA Single Reporting Platform works
The CRA platform gives manufacturers one electronic entry point that routes a notification to the coordinating CSIRT and ENISA.
Editorial date -
What are the responsibilities of the manufacturer, ENISA, and coordinating CSIRT in CRA reporting?
Who does what in the CRA reporting chain?
Manufacturers submit; ENISA manages the platform; coordinating CSIRTs receive, assess, and ordinarily disseminate Article 14 notifications.
Editorial date -
How does an EU-established manufacturer choose the coordinating CSIRT for CRA Article 14 reporting?
How to choose the CRA coordinating CSIRT
For an EU-established manufacturer, the CRA starts with the Member State where product-cybersecurity decisions are predominantly taken.
Editorial date -
Where does a CRA Article 14 notification go after a manufacturer submits it?
Where a CRA report goes after submission
The coordinating CSIRT ordinarily shares a CRA notification with relevant CSIRTs where the affected product was made available.
Editorial date -
When can onward dissemination of a CRA Article 14 notification be delayed?
CRA delayed dissemination is an exceptional route
A coordinating CSIRT may delay onward dissemination only under the CRA's exceptional, justified cybersecurity conditions and for a strictly necessary period.
Editorial date -
Which coordinating CSIRT should a manufacturer without an EU main establishment use for CRA reporting?
How the CRA routes reports from non-EU manufacturers
A manufacturer with no EU main establishment follows an ordered CRA routing test based on its representative, importer, distributor, then users.
Editorial date -
How should a manufacturer prepare internal reporting continuity before an Article 14 clock begins?
Build continuity for CRA reporting access
Prepare an internal primary-and-backup submission path around the CRA's staged reporting deadlines without relying on unverified platform mechanics.
Editorial date -
Must a manufacturer file separate CRA notifications with ENISA and its coordinating CSIRT?
A CRA report is one submission, not two filings
Manufacturers submit once through the CRA platform, which routes the notification to the coordinating CSIRT and makes it available to ENISA.
Editorial date -
When and to whom must a manufacturer send a CRA user notification?
When the CRA requires an impacted-user notice
After awareness of an actively exploited vulnerability or severe product-security incident, the manufacturer must inform impacted users and sometimes all users.
Editorial date -
What content should a manufacturer include in a CRA user notice?
What a useful CRA user notice needs to say
A CRA user notice should identify the affected product and give deployable mitigation or corrective steps where those measures are necessary.
Editorial date -
When must a final-product manufacturer report an actively exploited vulnerability in a third-party component?
When a component vulnerability becomes your CRA report
A supplier's exploited flaw does not answer the final-product question; the manufacturer must establish whether its own product contains and is affected by it.
Editorial date -
What should a manufacturer do after identifying a vulnerability in a third-party component integrated into its product?
Build the CRA handoff to a component maintainer
The CRA requires manufacturers that identify an integrated-component vulnerability to report it upstream and address it in their own product.
Editorial date -
How should a manufacturer map a vulnerable component to affected product versions for CRA reporting?
Map vulnerable components to CRA product versions
CRA reporting needs product-specific information, so component evidence must resolve to shipped product versions rather than stop at a dependency name.
Editorial date -
How should a manufacturer keep identifiers coherent across an Article 14 reporting case?
Keep stable identifiers across a CRA reporting case
Use one internal case anchor to reconcile the manufacturer, product, affected versions, evidence, and staged Article 14 submissions.
Editorial date -
How should a manufacturer determine which Member States to identify in a CRA early warning?
Build the Member State record for a CRA warning
The CRA early warning identifies, where applicable, Member States where the manufacturer knows the product was made available.
Editorial date -
How should a manufacturer prepare vulnerability-awareness records before Article 14 reporting starts?
Build the pre-11 September 2026 exploitation baseline
Article 14 reporting applies from 11 September 2026, so manufacturers need a dated baseline that separates earlier evidence from later awareness events.
Editorial date -
Do CRA Article 14 reporting obligations apply to manufacturers established outside the European Union?
CRA reporting can apply to manufacturers outside the EU
Manufacturer location does not remove CRA reporting when an in-scope product is made available on the Union market.
Editorial date -
When does the CRA treat an importer or distributor as the manufacturer for reporting purposes?
When a CRA importer or distributor becomes the manufacturer
An importer or distributor takes manufacturer obligations, including Articles 13 and 14, when it uses its own name or trademark or substantially modifies the product.
Editorial date -
Which Article 14 reporting duties apply to an open-source software steward?
The CRA reporting boundary for open-source stewards
Article 24 links steward vulnerability reporting to development involvement and severe-incident reporting to development systems the steward provides.
Editorial date -
Does maintaining an open-source project make a person an open-source software steward under the CRA?
Is an open-source maintainer a CRA steward?
A CRA open-source software steward is a legal person providing systematic, sustained support for specified software intended for commercial activities.
Editorial date -
How should a manufacturer resolve conflicting evidence about whether a vulnerability is actively exploited under the CRA?
Resolve conflicting CRA exploitation signals
A CRA active-exploitation decision turns on reliable evidence of malicious use without the system owner's permission, not on a label or score alone.
Editorial date -
How should a manufacturer decide whether an enterprise security incident is also a CRA severe incident affecting a product?
Separate product-security events from enterprise incidents
CRA severe-incident reporting concerns an incident that affects or can affect a product's ability to protect specified data or functions, or enables malicious code.
Editorial date -
How should a product group identify the legal manufacturer that owns each CRA Article 14 decision?
Build a manufacturer register for CRA reporting
CRA Article 14 duties attach to the manufacturer of the affected product, so a reporting runbook needs a product-specific legal-entity map.
Editorial date -
What evidence should move between the early warning, 72-hour notification, and final CRA report?
Build a handoff packet for each CRA report stage
Preserve the approved facts, unresolved questions, and filing evidence at the early-warning, 72-hour, and final Article 14 stages.
Editorial date -
How should a manufacturer classify sensitive information in a CRA notification?
Classify CRA report sensitivity before submission
CRA 72-hour notifications indicate, where applicable, how sensitive the manufacturer considers the reported information to be.
Editorial date -
How should an organisation assess the same security event under both the CRA and NIS2?
Triage one event under both the CRA and NIS2
The same security event can require separate assessment under the CRA's product-manufacturer test and NIS2 rules applying to an affected entity.
Editorial date -
How should a manufacturer assess one event that may be both a CRA product incident and a GDPR personal data breach?
Triage a product incident under the CRA and GDPR
A security event may require both a CRA product-security assessment and a GDPR personal-data-breach assessment because the regimes ask different questions.
Editorial date -
When should a manufacturer or another person consider a voluntary CRA notification?
Decide when to use CRA voluntary reporting
CRA Article 15 permits voluntary notification of vulnerabilities, cyber threats, incidents, and near misses beyond the narrower mandatory Article 14 triggers.
Editorial date -
How should a manufacturer choose channels and prove that a CRA user notice reached the intended audience?
Prove delivery of a CRA user notice
CRA user communication is risk-based: manufacturers inform impacted users and, where appropriate, all users without implying that every case requires indiscriminate public disclosure.
Editorial date -
What must a manufacturer separate when planning for the CRA's 2026 and 2027 application dates?
Separate the CRA's 2026 and 2027 workstreams
CRA conformity-body provisions apply from 11 June 2026, Article 14 reporting from 11 September 2026, and most remaining provisions from 11 December 2027.
Editorial date -
How should a manufacturer prepare older products for CRA Article 14 reporting?
Bring legacy products into CRA reporting triage
CRA Article 14 reporting applies to in-scope products made available before 11 December 2027, not only to products launched after the main application date.
Editorial date -
What should a manufacturer record as the moment a corrective or mitigating measure becomes available for CRA reporting?
Record when a CRA corrective measure becomes available
For an actively exploited vulnerability, the CRA final report is due no later than 14 days after a corrective or mitigating measure becomes available.
Editorial date -
Does the CRA exempt a microenterprise or small enterprise from the 24-hour early-warning duty?
Do not mistake CRA small-business penalty relief for a deadline waiver
CRA Article 64 prevents fines for certain micro and small manufacturers that miss the 24-hour early-warning deadline, but it does not remove Article 14 reporting duties.
Editorial date -
What should a smaller manufacturer prepare before asking a CRA reporting helpdesk for support?
Prepare an effective request to a CRA reporting helpdesk
The CRA requires coordinating CSIRTs to provide helpdesk support for reporting, with particular attention to microenterprises and small and medium-sized enterprises.
Editorial date -
How should a manufacturer run an end-to-end exercise of its CRA Article 14 reporting capability?
Run a complete CRA reporting readiness exercise
CRA Article 14 reporting begins on 11 September 2026 and uses separate staged sequences for actively exploited vulnerabilities and severe incidents.
Editorial date