InsideCRA
InsideCRA › Articles › Article 17

Regulation (EU) 2024/2847 · Chapter

Article 17 — Other provisions related to reporting

Other provisions related to reporting: the plumbing around Articles 14–16.

LAW Official text — verbatim from the Official Journal snapshot; only the Official Journal is authentic.

1.1. ENISA may submit to the European cyber crisis liaison organisation network (EU-CyCLONe) established under Article 16 of Directive (EU) 2022/2555 information notified pursuant to Article 14(1) and (3) and Article 15(1) and (2) of this Regulation if such information is relevant for the coordinated management of large-scale cybersecurity incidents and crises at an operational level. For the purpose of determining such relevance, ENISA may consider technical analyses performed by the CSIRTs network, where available.

2.2. Where public awareness is necessary to prevent or mitigate a severe incident having an impact on the security of the product with digital elements or to handle an ongoing incident, or where disclosure of the incident is otherwise in the public interest, the CSIRT designated as coordinator of the relevant Member State may, after consulting the manufacturer concerned and, where appropriate, in cooperation with ENISA, inform the public about the incident or require the manufacturer to do so.

3.3. ENISA, on the basis of the notifications received pursuant to Article 14(1) and (3) and Article 15(1) and (2) of this Regulation, shall prepare, every 24 months, a technical report on emerging trends regarding cybersecurity risks in products with digital elements and submit it to the Cooperation Group established pursuant to Article 14 of Directive (EU) 2022/2555. The first such report shall be submitted within 24 months of the date of application of the obligations laid down in Article 14(1) and (3) of this Regulation. ENISA shall include relevant information from its technical reports in its report on the state of cybersecurity in the Union pursuant to Article 18 of Directive (EU) 2022/2555.

4.4. The mere act of notification in accordance with Article 14(1) and (3) or Article 15(1) and (2) shall not subject the notifying natural or legal person to increased liability.

5.5. After a security update or another form of corrective or mitigating measure is available, ENISA shall, in agreement with the manufacturer of the product with digital elements concerned, add the publicly known vulnerability notified pursuant to Article 14(1) or Article 15(1) of this Regulation to the European vulnerability database established pursuant to Article 12(2) of Directive (EU) 2022/2555.

6.6. The CSIRTs designated as coordinators shall provide helpdesk support in relation to the reporting obligations pursuant to Article 14 to manufacturers and in particular manufacturers that qualify as microenterprises or as small or medium-sized enterprises.

BINDING Source: Regulation (EU) 2024/2847 (Cyber Resilience Act) · publisher European Union · captured 2026-09-16 · snapshot sha256:27b7c6c64c773001… · CELEX 32024R2847

What this article does

Article 17 collects the remaining reporting provisions: ENISA may pass notified information to EU-CyCLONe where relevant to managing large-scale incidents and crises; the coordinating CSIRT may, after consulting the manufacturer, inform the public about a severe incident or have the manufacturer do so; ENISA prepares a technical trends report every 24 months; notifying does not by itself expose the notifier to increased liability; publicly known vulnerabilities are added to the European vulnerability database, in agreement with the manufacturer, once a fix or mitigation is available; and coordinating CSIRTs offer helpdesk support on Article 14 reporting, in particular to micro, small and medium-sized enterprises.

Where to look operationally

For a manufacturer mid-incident, the operational documentation has moved closer to the ground than the Regulation text: ENISA's platform guidance covers registration, submission and update flows in concrete terms F-038. Articles 14 and 16 are the legal scaffolding those flows hang from F-031; Article 17 covers what can happen around a notification afterwards, so read it once, then work from the platform documentation F-038.

Verified facts this page relies on

Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).

Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.

Related in the reference

This area is still moving. Track changes with CEMarque Watch.