CRA Article 14 reporting guide for 11 September 2026
Understand the awareness clock, staged notifications and ENISA Single Reporting Platform before an actively exploited vulnerability or severe security incident creates a live deadline.
Last verified against EU / ENISA primary sources: 26 August 2026The short answer
CRA Article 14 reporting obligations apply from 11 September 2026. Manufacturers of products with digital elements must prepare to report actively exploited vulnerabilities and severe incidents having an impact on product security without undue delay through the CRA reporting process. Open-source software stewards also have reporting duties to the extent specified by the CRA.
They are outer limits. Article 14 uses a without-undue-delay standard, so the filing process should begin as soon as the relevant awareness threshold is reached.
Which events enter the Article 14 flow?
Actively exploited vulnerability
A vulnerability for which reliable evidence shows that a malicious actor has exploited it in a system without the system owner's permission. Evidence and awareness must be assessed on the actual facts.
Severe security incident
An incident meeting the CRA severity criteria and having an impact on the security of a product with digital elements. Availability, authenticity, integrity and confidentiality effects can be relevant.
Not every vulnerability or incident follows the same mandatory Article 14 route. If classification is uncertain, preserve the evidence and escalate for manual legal and security review instead of forcing a yes/no label.
The reporting stages
The final-report clock is not one universal 30-day rule. It depends on whether the track concerns an actively exploited vulnerability or a severe incident.
Early warning after awareness. This is an outer limit and the report must be made without undue delay.
Vulnerability or incident notification with the required general information and initial assessment.
For a vulnerability, no later than 14 days after a corrective or mitigating measure is available. For a severe incident, within one month after the incident notification. Confirm the correct anchor and current instructions before filing.
ENISA Single Reporting Platform context
ENISA describes the CRA SRP as the single electronic entry point for these notifications. It is scheduled to be operational from 11 September 2026. The platform routes the report to the selected coordinator CSIRT, determined using establishment rules, and to ENISA.
ENISA's user guidance can change as the platform launches. Confirm current registration, Assigned Representative, EU Login, routing and submission instructions directly with ENISA before relying on an internal procedure.
Lean operational readiness checklist
Use this checklist before an event occurs. It does not ask for incident details and does not generate or submit a report.
- Name the owner who records and preserves the exact awareness timestamp and timezone.
- Assign a technical and legal owner for event classification and uncertain-case escalation.
- Assign separate owners and backups for the 24-hour, 72-hour and final-report stages.
- Keep product, model, version, market and responsible-entity information accessible under time pressure.
- Prepare inputs for impact, exploitation, corrective or mitigating measures and user actions where relevant.
- Confirm SRP access, EU Login and Assigned Representative arrangements where applicable.
- Document the coordinator-CSIRT and internal approval routing that applies to the reporting entity.
- Retain submission confirmations, timestamps, versions and the evidence supporting key decisions.
What about products already on the market?
Do not assume that every product made available before the CRA's broader December 2027 application is automatically outside Article 14 reporting. Commission implementation material addresses pre-application products and awareness timing. Review the exact product, role, support and awareness facts against the current official guidance.
CRA reporting FAQ
Does this guide decide whether an event is reportable?
No. It explains the main event paths and readiness controls. Classification depends on evidence and the CRA definitions and may require manual legal and security review.
Does OneMinuteTools submit anything to the SRP?
No. This guide collects no incident information. The deadline calculator processes entered dates and times locally in the browser and does not imitate or submit to the SRP.
Can I wait until the 24-hour mark?
The rule is without undue delay and in any event within the outer limit. Operational plans should support earlier action rather than treating the limit as a target.
Primary sources
What changed
- — Published the lean Article 14 readiness guide, reconfirmed the 11 September date and current ENISA SRP material, and linked the guide to the live deadline calculator.