Reporting obligations of manufacturers under Article 14 of Regulation (EU) 2024/2847 (Cyber Resilience Act). A manufacturer notifies any actively exploited vulnerability contained in its product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator and to ENISA, via the single reporting platform (SRP) established under Article 16 (Art. 14(1)). The early warning and vulnerability notification deadlines run from the moment the manufacturer becomes aware of the vulnerability (T0, awareness). It submits: an early warning notification without undue delay and in any event within 24 hours (Art. 14(2)(a)); a vulnerability notification within 72 hours, with general information about the product, the general nature of the exploit and of the vulnerability, any corrective or mitigating measures taken, and those that users can take (Art. 14(2)(b)); and a final report no later than 14 days after a corrective or mitigating measure is available (Art. 14(2)(c)). A severe incident having an impact on the security of the product is notified in the same way (Art. 14(3)): an early warning within 24 hours, an incident notification within 72 hours and a final report within one month after the incident notification (Art. 14(4)).
Application calendar of Regulation (EU) 2024/2847. 10 December 2024: entry into force (Art. 71(1)). 11 June 2026: Chapter IV (Articles 35 to 51) on the notification of conformity assessment bodies applies (Art. 71(2)). 11 September 2026: Article 14 applies (Art. 71(2)), including to all products with digital elements that fall within the scope of the Regulation and were placed on the market before 11 December 2027 (Art. 69(3)). 11 December 2027: the Regulation applies in full, including the essential requirements, conformity assessment and CE marking (Art. 71(2)). Non-compliance with the essential cybersecurity requirements in Annex I and the obligations in Articles 13 and 14 is subject to administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 2.5% of its total worldwide annual turnover for the preceding financial year, whichever is higher (Art. 64(2)). The Article 64 fines apply from 11 December 2027 (Art. 71(2)). By way of derogation from paragraphs 2 to 9 (Art. 64(10), as corrected on 2 July 2025), the administrative fines do not apply to: manufacturers that qualify as microenterprises or small enterprises, only with regard to any failure to meet the 24-hour early-warning deadline (Art. 14(2)(a) and 14(4)(a); Art. 64(10)(a)); any infringement of the Regulation by open-source software stewards (Art. 64(10)(b)).
AnnexProof in 4 steps (product information, not legal advice): 1) import the product’s software bill of materials (SBOM); 2) daily vulnerability monitoring of its components; 3) an alert with the Article 14 reporting deadlines when a vulnerability may need a notification: 24 and 72 hours from awareness, and 14 days after a corrective or mitigating measure is available; 4) technical documentation following Annex VII (Art. 31) and prepared notification packets for submission via the single reporting platform.