EU CRA Article 14: The 24-Hour Exploited-Vulnerability Reporting Rule, Explained

A plain-language walkthrough for a solo founder or small software vendor who just found out this applies to them and has no compliance team to hand it to.

Updated 2026-09-12 — Article 14 took effect 2026-09-11.

The short version: if you sell software (or a connected/IoT product) into the EU and you learn one of your dependencies has an actively exploited vulnerability, you have 24 hours to send ENISA (and your national CSIRT) an early-warning notification, a follow-up within 72 hours, and a final report within 14 days of the fix being available.

Who does this actually apply to?

The Cyber Resilience Act (Regulation (EU) 2024/2847) covers "products with digital elements" placed on the EU market — which in practice means almost any software or connected hardware sold to EU customers, not just critical infrastructure or big enterprise vendors. If you have even one paying EU customer for a SaaS product, a plugin, a mobile app, or a device with firmware, you're in scope. There's no small- business carve-out for the reporting obligation itself, though enforcement priorities in the first year are widely expected to focus on larger or higher-risk vendors first. This is not legal advice — see the disclaimer below — but the plain text of the Regulation does not exempt small vendors from Article 14.

What triggers the clock?

Two separate triggers exist under Article 14, and they're easy to conflate:

Most small vendors will encounter the first case: a dependency they ship (a library, a framework, an OS package) gets a CVE added to a known-exploited list, and now the clock is running on their product, even though they didn't write the vulnerable code.

The three deadlines

ReportDeadlineWhat it contains
Early warning24 hours from awarenessBasic facts: what's affected, that it's being exploited, cross-border relevance if known
Follow-up notification72 hours from awarenessUpdated assessment, initial indicators of compromise, corrective measures taken/planned
Final report14 days after a fix is availableFull description, severity, impact, and remediation details

"Awareness" is the operative word for the clock start — not when the CVE was published, but when you became aware it applies to your product. That's exactly the gap a monitoring tool closes: most small vendors aren't watching CISA's or ENISA's feeds daily, so "awareness" can arrive days late purely from not checking.

What you actually have to do, in order

Where the risk actually is for a small vendor

It's not the reporting itself — ENISA's forms are short. It's missing the clock entirely because nobody on a two-person team is checking a government vulnerability feed every day on top of shipping product. Penalties for non-compliance run up to €15M or 2.5% of global annual turnover, though realistically first-year enforcement focus and proportionality provisions matter — this piece isn't legal advice on your specific exposure.

A free way to check your own exposure right now

ExploitWatch checks CISA's KEV catalog against a plain-text list of your dependencies, free, with no signup. If you want it checked daily going forward — so you find out the moment something matches instead of finding out when it's already a problem — that's the $19/mo version below.

Try the free check →
This is not legal advice. This page is a plain-language summary for orientation purposes only. Whether Article 14 applies to your specific product, what counts as "awareness" in your situation, and how to file with ENISA or your national CSIRT are legal questions that depend on your facts. Consult qualified counsel. ExploitWatch is a monitoring aid, not a compliance guarantee.

ExploitWatch home · Privacy · Terms