AEV
Actively exploited vulnerability
Article 3 defines this as a vulnerability for which reliable evidence shows malicious exploitation in a system without the system owner’s permission.
CRA Article 14
Article 14 of Regulation (EU) 2024/2847 sets reporting obligations for manufacturers that become aware of specified vulnerabilities or incidents involving products with digital elements.
Official links checked 23 August 2026.
Begin with the occurrence
The regulation’s definitions and thresholds control the assessment. ActLume can organise the evidence, but a responsible person must assess the facts for the manufacturer.
AEV
Article 3 defines this as a vulnerability for which reliable evidence shows malicious exploitation in a system without the system owner’s permission.
SI
Article 14 applies when the incident meets the regulation’s severe-impact conditions. The legal criteria, not a software label, determine the result.
Reporting stages
The hour limits below are outer limits after awareness. They are not permission to wait. The final-report trigger differs between the vulnerability and incident paths.
24 hours
Without undue delay and in any event within 24 hours after the manufacturer becomes aware of the actively exploited vulnerability or severe incident.
72 hours
Without undue delay and in any event within 72 hours after awareness, with the available general information, assessment, and mitigation content required for the path.
Final
No later than 14 days after a corrective or mitigating measure becomes available, unless the required information was already provided.
Final
Within one month after submission of the incident notification. This page preserves the regulation’s wording rather than substituting a calculated date.
General information, not legal advice
Scope, awareness, severity, timing, routing, and required content depend on the controlling law and the facts. Use the official text and qualified legal review for decisions.
Where ActLume fits
ActLume will keep intake, reportability, awareness, staged preparation, handoff readiness, and confirmed submission as separate states.
It will open ENISA SRP and EU Login separately. The filer signs in there, transfers selected values, reviews the portal content, submits, and records the result in ActLume.
See the planned workflowOfficial sources
The controlling text of Regulation (EU) 2024/2847, including Article 14.
The European Commission implementation timeline and current guidance entry points.
ENISA information about the CRA Single Reporting Platform and its reporting workflow.
ENISA guidance may change as the reporting platform is implemented. Check the official provider page for the current operational position.
Browse practical Article 14 guides