{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 2,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/obligation.json",
  "self": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-cra-art14.json",
  "source": "https://aigovernanceengineer.com/obligations/aige-obl-cra-art14",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "obligation": {
    "id": "AIGE-OBL-CRA-ART14",
    "url": "https://aigovernanceengineer.com/obligations/aige-obl-cra-art14",
    "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-cra-art14.json",
    "framework": "Cyber Resilience Act",
    "frameworkId": "eu-cra",
    "clause": "Art. 14",
    "obligation": "Cyber Resilience Act Art. 14 reporting of actively exploited vulnerabilities and severe incidents",
    "requirement": "Notify actively exploited vulnerabilities and severe incidents through the single reporting platform: early warning within 24 hours, notification within 72 hours, final report 14 days after a fix is available (vulnerability) or one month after the notification (incident)",
    "artefact": "Vulnerability and incident clocks on the incident record; submission through the single reporting platform",
    "layers": [
      4,
      5
    ],
    "dutyHolder": null,
    "scope": "Manufacturers of products with digital elements",
    "authority": "Coordinating CSIRT and ENISA",
    "appliesFrom": "2026-09-11",
    "appliesStatus": "in-force",
    "appliesNote": "Art. 14 applies from 2026-09-11; the rest of the Regulation from 2027-12-11",
    "milestones": [
      {
        "date": "2027-12-11",
        "systemClass": [],
        "note": "The rest of the Regulation applies"
      }
    ],
    "systemClass": [],
    "patterns": [],
    "crosswalkTopics": [],
    "reviewed": "2026-09-24",
    "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#cyber-security-and-incident-reporting-law"
  }
}
