Cyber Resilience Act · Article 14

Reporting obligations of manufacturers

Binds
manufacturer
Applies from
Evidence
process

Article 14(1): Reporting obligations of manufacturers

manufacturer · Article 14(1)

Reporting obligations of manufacturers 1. A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. The manufacturer shall notify that actively exploited vulnerability via the single reporting platform established pursuant to Article 16.

How to satisfy it: The forcing function: this applies from 11 September 2026, fifteen months before the rest of the Regulation. Notification is simultaneous to the coordinating CSIRT and ENISA, via the single reporting platform under Article 16, and paragraph 2 sets a staged early- warning then follow-up sequence.

Article 14(1) on EUR-Lex · as of 2026-08-13 · Regulation (EU) 2024/2847

Article 14(2): Reporting obligations of manufacturers

manufacturer · Article 14(2)

For the purposes of the notification referred to in paragraph 1, the manufacturer shall submit: (a) an early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available; (b) unless the relevant information has already been provided, a vulnerability notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the actively exploited vulnerability, which shall provide general information, as available, about the product with digital elements concerned, the general nature of the exploit and of the vulnerability concerned as well as any corrective or mitigating measures taken, and corrective or mitigating measures that users can take, and which shall also indicate, where applicable, how sensitive the manufacturer considers the notified information to be; (c) unless the relevant information has already been provided, a final report, no later than 14 days after a corrective or mitigating measure is available, including at least the following: (i) a description of the vulnerability, including its severity and impact; (ii) where available, information concerning any malicious actor that has exploited or that is exploiting the vulnerability; (iii) details about the security update or other corrective measures that have been made available to remedy the vulnerability.

How to satisfy it: The three filings for an exploited vulnerability: 24h early warning, 72h vulnerability notification, and a final report no later than 14 days after a corrective or mitigating measure IS AVAILABLE. The 14-day clock runs from the remedy, not from awareness, and computing it from awareness invents a deadline the Regulation does not impose.

Article 14(2) on EUR-Lex · as of 2026-08-13 · Regulation (EU) 2024/2847

Article 14(3): Reporting obligations of manufacturers

manufacturer · Article 14(3)

A manufacturer shall notify any severe incident having an impact on the security of the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. The manufacturer shall notify that incident via the single reporting platform established pursuant to Article 16.

How to satisfy it: The second reporting duty, distinct from 14(1). A severe incident is defined in 14(5) and requires no vulnerability at all, so a tool that only watches CVEs cannot see it.

Article 14(3) on EUR-Lex · as of 2026-08-13 · Regulation (EU) 2024/2847

Article 14(4): Reporting obligations of manufacturers

manufacturer · Article 14(4)

For the purposes of the notification referred to in paragraph 3, the manufacturer shall submit: (a) an early warning notification of a severe incident having an impact on the security of the product with digital elements, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, including at least whether the incident is suspected of being caused by unlawful or malicious acts, which shall also indicate, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available; (b) unless the relevant information has already been provided, an incident notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the incident, which shall provide general information, where available, about the nature of the incident, an initial assessment of the incident, as well as any corrective or mitigating measures taken, and corrective or mitigating measures that users can take, and which shall also indicate, where applicable, how sensitive the manufacturer considers the notified information to be; (c) unless the relevant information has already been provided, a final report, within one month after the submission of the incident notification under point (b), including at least the following: (i) a detailed description of the incident, including its severity and impact; (ii) the type of threat or root cause that is likely to have triggered the incident; (iii) applied and ongoing mitigation measures.

How to satisfy it: The three filings for a severe incident. NOT the same shape as 14(2): the final report is due within ONE MONTH after the incident notification under point (b) was submitted, not 14 days after a remedy. The 24h notification must additionally state whether unlawful or malicious acts are suspected.

Article 14(4) on EUR-Lex · as of 2026-08-13 · Regulation (EU) 2024/2847

Article 14(5): Reporting obligations of manufacturers

manufacturer · Article 14(5)

For the purposes of paragraph 3, an incident having an impact on the security of the product with digital elements shall be considered to be severe where: (a) it negatively affects or is capable of negatively affecting the ability of a product with digital elements to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions; or (b) it has led or is capable of leading to the introduction or execution of malicious code in a product with digital elements or in the network and information systems of a user of the product with digital elements.

How to satisfy it: The gate on 14(3). Two limbs, either sufficient, and both read 'or is capable of': an incident that COULD have had these effects qualifies even if it did not.

Article 14(5) on EUR-Lex · as of 2026-08-13 · Regulation (EU) 2024/2847

Article 14(6): Reporting obligations of manufacturers

manufacturer · Article 14(6)

Where necessary, the CSIRT designated as coordinator initially receiving the notification may request manufacturers to provide an intermediate report on relevant status updates about the actively exploited vulnerability or severe incident having an impact on the security of the product with digital elements.

How to satisfy it: On request from the CSIRT coordinator, the manufacturer must supply status updates. It cannot be scheduled in advance, so a process has to exist that can answer it.

Article 14(6) on EUR-Lex · as of 2026-08-13 · Regulation (EU) 2024/2847

Article 14(7): Reporting obligations of manufacturers

manufacturer · Article 14(7)

The notifications referred to in paragraphs 1 and 3 of this Article shall be submitted via the single reporting platform referred to in Article 16 using one of the electronic notification end-points referred to in Article 16(1). The notification shall be submitted using the electronic notification end-point of the CSIRT designated as coordinator of the Member State where the manufacturers have their main establishment in the Union and shall be simultaneously accessible to ENISA. For the purposes of this Regulation, a manufacturer shall be considered to have its main establishment in the Union in the Member State where the decisions related to the cybersecurity of its products with digital elements are predominantly taken. If such a Member State cannot be determined, the main establishment shall be considered to be in the Member State where the manufacturer concerned has the establishment with the highest number of employees in the Union. Where a manufacturer has no main establishment in the Union, it shall submit the notifications referred to in paragraphs 1 and 3 using the electronic notification end-point of the CSIRT designated as coordinator in the Member State determined pursuant to the following order and based on the information available to the manufacturer: (a) the Member State in which the authorised representative acting on behalf of the manufacturer for the highest number of products with digital elements of that manufacturer is established; (b) the Member State in which the importer placing on the market the highest number of products with digital elements of that manufacturer is established; (c) the Member State in which the distributor making available on the market the highest number of products with digital elements of that manufacturer is established; (d) the Member State in which the highest number of users of products with digital elements of that manufacturer are located. In relation to the third subparagraph, point (d), a manufacturer may submit notifications related to any subsequent actively exploited vulnerability or severe incident having an impact on the security of the product with digital elements to the same CSIRT designated as coordinator to which it first reported.

How to satisfy it: Which CSIRT receives the filing. Determined by main establishment, meaning where decisions on product cybersecurity are predominantly taken, with a four-step fallback for manufacturers with no establishment in the Union.

Article 14(7) on EUR-Lex · as of 2026-08-13 · Regulation (EU) 2024/2847

Article 14(8): Reporting obligations of manufacturers

manufacturer · Article 14(8)

After becoming aware of an actively exploited vulnerability or a severe incident having an impact on the security of the product with digital elements, the manufacturer shall inform the impacted users of the product with digital elements, and where appropriate all users, of that vulnerability or incident and, where necessary, of any risk mitigation and corrective measures that the users can deploy to mitigate the impact of that vulnerability or incident, where appropriate in a structured, machine-readable format that is easily automatically processable. Where the manufacturer fails to inform the users of the product with digital elements in a timely manner, the notified CSIRTs designated as coordinators may provide such information to the users when considered to be proportionate and necessary for preventing or mitigating the impact of that vulnerability or incident.

How to satisfy it: A duty owed to USERS, separate from notifying the CSIRT coordinator and ENISA, and easy to miss because it sits after the notification paragraphs. Impacted users must be informed of the vulnerability or incident and of mitigations they can deploy, where appropriate in a structured, machine-readable format.

Article 14(8) on EUR-Lex · as of 2026-08-13 · Regulation (EU) 2024/2847

Every quoted requirement on this page is verbatim Official Journal text. The surrounding guidance is Legalithm’s commentary and is not regulation. This page states the obligation and its legal basis; it is not legal advice, and the corpus has not been reviewed by counsel.