Cyber Resilience Act Art. 14: reporting of actively exploited vulnerabilities and severe incidents
Notify actively exploited vulnerabilities and severe incidents through the single reporting platform: early warning within 24 hours, notification within 72 hours, final report 14 days after a fix is available (vulnerability) or one month after the notification (incident)
AIGE-OBL-CRA-ART14. Drawn from chapter 08.
Text alternative
- Clause: CRA, Art. 14.
- Duty holder: Manufacturers of products….
- Applies from: 2026-09-11, In force.
- Artefact: Vulnerability and incident clocks….
- Layers: Layer 04, Layer 05.
- Evidence record: Evidence record v1.
- Record schema: Evidence record.
- No crosswalk topic files this clause yet.
- Id
AIGE-OBL-CRA-ART14- Instrument
- Cyber Resilience Act (EU) 2024/2847 law
- Clause
- Art. 14
- In scope
- Manufacturers of products with digital elements
- Authority
- Coordinating CSIRT and ENISA
- Applies from
- In force · Art. 14 applies from 2026-09-11; the rest of the Regulation from 2027-12-11
- Later dates
-
- The rest of the Regulation applies
The artefact that evidences it
Vulnerability and incident clocks on the incident record; submission through the single reporting platform.
Patterns that build it
No pattern in the catalogue names this clause on its "Maps to" line yet; the artefact above is the engineering answer.
Source
Chapter 08, section Cyber-security and incident-reporting law, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-cra-art14.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). Cyber Resilience Act Art. 14: reporting of actively exploited vulnerabilities and severe incidents (AIGE-OBL-CRA-ART14). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-cra-art14. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{Cyber Resilience Act Art. 14: reporting of actively exploited vulnerabilities and severe incidents (AIGE-OBL-CRA-ART14)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-cra-art14},
note = {Version 0.5.0}
}