InsideCRA
InsideCRA › Articles › Article 15

Regulation (EU) 2024/2847 · Chapter

Article 15 — Voluntary reporting

Voluntary reporting: the open channel for everything Article 14 does not compel.

LAW Official text — verbatim from the Official Journal snapshot; only the Official Journal is authentic.

1.1. Manufacturers as well as other natural or legal persons may notify any vulnerability contained in a product with digital elements as well as cyber threats that could affect the risk profile of a product with digital elements on a voluntary basis to a CSIRT designated as coordinator or ENISA.

2.2. Manufacturers as well as other natural or legal persons may notify any incident having an impact on the security of the product with digital elements as well as near misses that could have resulted in such an incident on a voluntary basis to a CSIRT designated as coordinator or ENISA.

3.3. The CSIRT designated as coordinator or ENISA shall process the notifications referred to in paragraphs 1 and 2 of this Article in accordance with the procedure laid down in Article 16.
The CSIRT designated as coordinator may prioritise the processing of mandatory notifications over voluntary notifications.

4.4. Where a natural or legal person other than the manufacturer notifies an actively exploited vulnerability or a severe incident having an impact on the security of a product with digital elements in accordance with paragraph 1 or 2, the CSIRT designated as coordinator shall without undue delay inform the manufacturer.

5.5. The CSIRTs designated as coordinators as well as ENISA shall ensure the confidentiality and appropriate protection of the information provided by a notifying natural or legal person. Without prejudice to the prevention, investigation, detection and prosecution of criminal offences, voluntary reporting shall not result in the imposition of any additional obligations upon a notifying natural or legal person to which it would not have been subject had it not submitted the notification.

BINDING Source: Regulation (EU) 2024/2847 (Cyber Resilience Act) · publisher European Union · captured 2026-09-16 · snapshot sha256:27b7c6c64c773001… · CELEX 32024R2847

What this article does

Article 15 opens a voluntary lane beside Article 14's mandatory one: manufacturers — and others, including users and researchers — may report vulnerabilities, incidents and near misses that no clock compels them to report. Voluntary notifications go to a CSIRT designated as coordinator or to ENISA, which process them under the Article 16 procedure; the coordinator may prioritise mandatory notifications over voluntary ones.

Why volunteer

Three reasons show up in practice. A borderline event can be put in front of a coordinator early, while it is still unclear whether the Article 14 clocks, which run from awareness, have started F-028. When someone other than the manufacturer reports an actively exploited vulnerability or a severe incident, the coordinator informs the manufacturer without undue delay. And researchers get an official door that is not a manufacturer's silence.

The safeguard: without prejudice to criminal investigations and prosecutions, a voluntary report does not impose on the person who made it any additional duties they would not otherwise have had, and the coordinators and ENISA protect the confidentiality of what reporters provide.

Verified facts this page relies on

Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).

Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.

Related in the reference

This area is still moving. Track changes with CEMarque Watch.