Topic
Article 14 reporting, end to end
The live obligation: triggers, clocks, platform, and user notification.
This is the part of the Regulation that is already real: reporting applies from 11 September 2026 F-002.
The flow has four stations. Trigger: an actively exploited vulnerability or a severe incident affecting the product's security, both defined terms F-030. Clock: early warning within 24 hours of awareness, notification within 72 hours, final report within 14 days after a corrective or mitigating measure is available for a vulnerability, or within one month after the incident notification for a severe incident F-028 F-029. Channel: the ENISA single reporting platform, through which notifications go to the CSIRT designated as coordinator F-031 and are simultaneously accessible to ENISA under Article 14(7). Audience: impacted users, and where relevant all users, are informed of the vulnerability or incident and, where necessary, of risk-mitigating and corrective measures F-032.
What a working setup looks like
Someone owns awareness — a monitored intake, so the clock starts on signal, not on the next stand-up F-028. Platform registration is done in calm weather F-038. And a drafted early-warning template exists, because 24 hours is a short time to write your first one F-028.
Verified facts this page relies on
- F-002 Article 14 (reporting obligations of manufacturers) applies from 11 September 2026. Art. 71(2)
- F-028 Actively exploited vulnerability: early warning within 24 hours of awareness; notification within 72 hours; final report within 14 days after a corrective or mitigating measure is available. Art. 14(1)–(2)
- F-029 Severe incident having an impact on the security of the product: early warning within 24 hours; incident notification within 72 hours; final report within one month after the incident notification. Art. 14(3)–(4)
- F-030 Actively exploited vulnerability (Art. 3(42)): reliable evidence that a malicious actor has exploited it in a system without the system owner's permission. A severe incident having an impact on the security of the product (Art. 14(5)) is one that negatively affects or is capable of negatively affecting the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or that has led or is capable of leading to the introduction or execution of malicious code. Art. 3(42), Art. 3(44), Art. 14(5)
- F-031 Notifications are submitted through the ENISA single reporting platform to the CSIRT designated as coordinator in the Member State where the manufacturer has its main establishment; a manufacturer without an EU establishment uses the Member State of its authorised representative, or where the product is made available. Art. 14(7), Art. 16
- F-032 After becoming aware of an actively exploited vulnerability or severe incident, the manufacturer informs impacted users, and where appropriate all users, without undue delay, including risk-mitigating and corrective measures. Art. 14(8)
- F-038 ENISA single reporting platform: the Assigned Representative guidance pages (user registration; notification submission and update; interface functions) were updated on 9 September 2026, alongside guidance on particularly exceptional circumstances under the third subparagraph of Article 16(2), an AR user manual, an SRP glossary, terms and conditions and the list of CSIRTs designated as coordinators; from 11 September 2026 manufacturers are required to submit Article 14 notifications through the platform. ENISA
Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).
Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.
Related in the reference
- Article 14 — Reporting obligations of manufacturers
- Article 16 — Establishment of a single reporting platform
- Definition: Actively exploited vulnerability
- Definition: Severe incident having an impact on the security of the product