ActLume blog
Practical guidance for CRA Article 14 reporting.
Understand manufacturer readiness, incident coordination, deadlines, staged reports, and the human-controlled ENISA SRP handoff.
CRA Article 14 reporting stages and deadlines
Both Article 14 tracks start with 24-hour and 72-hour stages, but their final-report clocks start from different events.
Published articles
50 available Subscribe via RSS
-
When does the CRA Article 14 reporting clock start for a manufacturer?
When does the CRA Article 14 clock start?
The CRA Article 14 clock starts when an initial assessment gives the manufacturer reasonable certainty that an actively exploited vulnerability or severe incident meets the reporting trigger.
-
What makes a vulnerability actively exploited for CRA Article 14 reporting?
CRA actively exploited vulnerabilities explained
An actively exploited vulnerability requires reliable evidence that a malicious actor exploited a vulnerability without the system owner's permission.
-
How should a manufacturer test whether an incident is severe under CRA Article 14?
The CRA severe product-security incident test
Article 14 treats an incident as severe when it meets either of two product-security impact tests concerning protected data, functions, or malicious code.
-
What should a manufacturer prepare for the CRA Article 14 24-hour early warning?
What belongs in a CRA 24-hour early warning?
The first Article 14 stage is an early warning due without undue delay and within 24 hours of awareness, not a finished investigation report.
-
What information belongs in the CRA 72-hour vulnerability notification?
Prepare the CRA 72-hour vulnerability notification
The 72-hour vulnerability stage adds available product, exploit, vulnerability, mitigation, user-action, and sensitivity information.
-
What should a manufacturer prepare for the CRA 72-hour severe-incident notification?
Prepare the CRA 72-hour incident notification
The 72-hour incident stage carries available general information, an initial assessment, and corrective or mitigating measures.
-
What starts the CRA deadline for an actively exploited vulnerability final report?
When is the CRA vulnerability final report due?
The final report for an actively exploited vulnerability is due no later than 14 days after a corrective or mitigating measure becomes available.
-
What starts the CRA final-report deadline for a severe product-security incident?
When is the CRA severe-incident final report due?
The final report for a severe incident is due within one month after the 72-hour incident notification.
-
Why should a manufacturer assess the two CRA Article 14 reporting tracks separately?
The CRA has two Article 14 reporting tracks
Article 14 separately covers actively exploited vulnerabilities and severe incidents affecting product security, with distinct final-report rules.
-
What should a manufacturer do when facts are incomplete at the CRA 24-hour reporting stage?
What if CRA facts are incomplete at 24 hours?
The CRA early warning comes before the fuller 72-hour notification, so teams need a controlled way to report known facts and preserve uncertainty.
-
How should a manufacturer maintain evidence across the stages of a CRA Article 14 report?
Keep one evidence trail through CRA reporting
CRA notifications develop across the 24-hour, 72-hour, and final stages, making a traceable record of additions and corrections essential.
-
How should a manufacturer preserve and reconcile the timestamps behind a CRA awareness record?
Record the CRA awareness timestamp
A CRA awareness record needs more than one timestamp. Preserve raw source and receipt times, record clock quality, and explain how the chosen instant was normalised to UTC.