CRA Article 14

Start with the law, then record the manufacturer’s decision.

Article 14 of Regulation (EU) 2024/2847 sets reporting obligations for manufacturers that become aware of specified vulnerabilities or incidents involving products with digital elements.

Official links checked 23 August 2026.

Begin with the occurrence

Article 14 has two reporting paths.

The regulation’s definitions and thresholds control the assessment. ActLume can organise the evidence, but a responsible person must assess the facts for the manufacturer.

AEV

Actively exploited vulnerability

Article 3 defines this as a vulnerability for which reliable evidence shows malicious exploitation in a system without the system owner’s permission.

SI

Severe incident affecting product security

Article 14 applies when the incident meets the regulation’s severe-impact conditions. The legal criteria, not a software label, determine the result.

Reporting stages

The 24- and 72-hour limits are not waiting periods.

The hour limits below are outer limits after awareness. They are not permission to wait. The final-report trigger differs between the vulnerability and incident paths.

24 hours

Early warning

Without undue delay and in any event within 24 hours after the manufacturer becomes aware of the actively exploited vulnerability or severe incident.

72 hours

Notification

Without undue delay and in any event within 72 hours after awareness, with the available general information, assessment, and mitigation content required for the path.

Final

Vulnerability path

No later than 14 days after a corrective or mitigating measure becomes available, unless the required information was already provided.

Final

Incident path

Within one month after submission of the incident notification. This page preserves the regulation’s wording rather than substituting a calculated date.

General information, not legal advice

Scope, awareness, severity, timing, routing, and required content depend on the controlling law and the facts. Use the official text and qualified legal review for decisions.

Where ActLume fits

Prepare in ActLume, then file in SRP.

ActLume will keep intake, reportability, awareness, staged preparation, handoff readiness, and confirmed submission as separate states.

It will open ENISA SRP and EU Login separately. The filer signs in there, transfers selected values, reviews the portal content, submits, and records the result in ActLume.

See the planned workflow

Official sources

Check the current official text.

ENISA guidance may change as the reporting platform is implemented. Check the official provider page for the current operational position.

Browse practical Article 14 guides