Cyber Resilience Act Art. 14: reporting of actively exploited vulnerabilities and severe incidents

Notify actively exploited vulnerabilities and severe incidents through the single reporting platform: early warning within 24 hours, notification within 72 hours, final report 14 days after a fix is available (vulnerability) or one month after the notification (incident)

From clause to evidenceThe chain from CRA Art. 14 to its evidence record, in 6 steps; the text alternative lists them and the facts under the figure state each in full.ClauseCRAArt. 14Duty holderManufacturersof products…Applies from2026-09-11In forceArtefactVulnerabilityand incident…LayersLayer 04Layer 05Evidence recordEvidence recordv1Same topic elsewhere: no crosswalk topic files this clause yetAs of 2026-09-24 · illustrative, not a claim of conformity From clause to evidenceThe chain from CRA Art. 14 to its evidence record, in 6 steps; the text alternative lists them and the facts under the figure state each in full.ClauseCRA · Art. 14Duty holderManufacturers of products…Applies from2026-09-11 · In forceArtefactVulnerability and incident clocks…LayersLayer 04Layer 05Evidence recordEvidence record v1Same topic elsewhere: no crosswalk topicfiles this clause yetAs of 2026-09-24illustrative, not a claim of conformity
From clause to evidence Build the artefact, then file every output it produces as a record that names AIGE-OBL-CRA-ART14. Drawn from chapter 08.
Text alternative
  • Clause: CRA, Art. 14.
  • Duty holder: Manufacturers of products….
  • Applies from: 2026-09-11, In force.
  • Artefact: Vulnerability and incident clocks….
  • Layers: Layer 04, Layer 05.
  • Evidence record: Evidence record v1.
  • Record schema: Evidence record.
  • No crosswalk topic files this clause yet.
Id
AIGE-OBL-CRA-ART14
Instrument
Cyber Resilience Act (EU) 2024/2847 law
Clause
Art. 14
In scope
Manufacturers of products with digital elements
Authority
Coordinating CSIRT and ENISA
Applies from
In force · Art. 14 applies from 2026-09-11; the rest of the Regulation from 2027-12-11
Later dates
  • The rest of the Regulation applies

The artefact that evidences it

Vulnerability and incident clocks on the incident record; submission through the single reporting platform.

Patterns that build it

No pattern in the catalogue names this clause on its "Maps to" line yet; the artefact above is the engineering answer.

Source

Chapter 08, section Cyber-security and incident-reporting law, checked against its sources on the review date above.

Machine-readable

Cite this obligation

García Aibar, J. (2026). Cyber Resilience Act Art. 14: reporting of actively exploited vulnerabilities and severe incidents (AIGE-OBL-CRA-ART14). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-cra-art14. CC BY 4.0

BibTeX

@misc{aige2026obligation,
  author       = {Jorge García Aibar},
  title        = {{Cyber Resilience Act Art. 14: reporting of actively exploited vulnerabilities and severe incidents (AIGE-OBL-CRA-ART14)}},
  howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
  year         = {2026},
  version      = {0.5.0},
  doi          = {10.5281/zenodo.22956197},
  url          = {https://aigovernanceengineer.com/obligations/aige-obl-cra-art14},
  note         = {Version 0.5.0}
}