
Article 14 · single reporting platform · 11 September 2026
From 11 September 2026 a manufacturer of a product with digital elements has 24 hours to send an early warning when it becomes aware of an actively exploited vulnerability in that product, or of a severe incident affecting its security. Then 72 hours for the notification, and a final report after that. The deadlines are short, the platform is ENISA's, and the recipient depends on where you are established. This page sets out what triggers the clock, what does not, and how to be ready before the date rather than after it.
24 hours72 hoursFinal reportENISA platformCSIRT

The first stage is the one that catches teams out, because 24 hours includes weekends and the trigger is becoming aware, not finishing the investigation. The early warning is deliberately short: it says something is happening, not what.

| Your situation | Coordinating CSIRT | What to prepare |
|---|---|---|
| Main establishment in the Union | That Member State's CSIRT | Account on the platform, named submitters |
| No establishment, authorised representative appointed | The representative's Member State | The mandate, and the representative's details in your runbook |
| No representative, importer of record | The importer's Member State | Confirmation from the importer that it accepts the role |
| No importer, distributor | The distributor's Member State | The same, one link further down the chain |
| None of these | Undetermined | Twenty-four hours spent finding out is twenty-four hours not spent fixing |
This table is the entire commercial argument for the optional mandate in Article 18, and it is why we describe that appointment as optional and worth signing rather than pretending it is required.
Write down who can declare it and on what evidence: exploitation observed in telemetry, a credible customer report, a public proof of concept in use. Without this, the clock starts in an argument.
At least two people with platform access, in different time zones if you have them. One person on holiday should not be a compliance failure.
Product, version, what is happening, whether it looks malicious, whether other Member States are affected. Five fields, drafted in advance.
The notification needs severity, impact and any corrective measures. Different author, different depth.
Where appropriate, users must be informed and told what they can do. Draft the template before you need it at 3am.
Timestamps of awareness, submission and updates. If the deadline is ever questioned, this is the answer.
| Regime | Trigger | First deadline | To whom |
|---|---|---|---|
| CRA Article 14 | Actively exploited vulnerability or severe incident affecting product security | 24 hours | Coordinating CSIRT via the single platform |
| NIS2 Article 23 | Significant incident affecting the service you operate | 24 hours | CSIRT or competent authority of your Member State |
| GDPR Article 33 | Personal data breach | 72 hours | The supervisory authority |
| GPSR Article 20 | Dangerous product placed on the market | Without delay | Market surveillance, through Safety Business Gateway |
A single event can trigger three of these at once. A ransomware intrusion that exploits a flaw in your own product, affects the cloud service you operate and exposes customer data is not a hypothetical, and the three reports go to three different places with two different clocks. Deciding who writes which one is a table-top exercise, not a policy document.
With the Article 18 mandate, the coordinating CSIRT is determined by our Member State, known in advance and written in your runbook.
Questions from market surveillance and the CSIRT reach us and are forwarded to you the same working day, in the language they arrived in.
Declaration of conformity and technical documentation, produced on a reasoned request without waiting for your office to open.
The early warning is yours. It needs facts only your security team has, and the platform expects the manufacturer.
Whether a vulnerability is actively exploited is a technical judgement inside your organisation.
Corrective measures and the support period are manufacturer duties under Article 13, expressly outside the mandate.
From 11 September 2026: 24 hours for the early warning, 72 for the notification, then the final report, through ENISA's single platform, to the CSIRT determined by where you are established or represented. Write the runbook now, name two submitters, define what counts as becoming aware, and if you have no establishment in the Union, sign the Article 18 mandate so the recipient is decided before the day you need it.
There is a version of this work that takes a fortnight and a version that takes six months. The difference is whether you treat it as a documentation exercise or as an operational one.
| Artefact | Effort | Why it pays |
|---|---|---|
| Definition of "becoming aware" | One meeting | Removes the argument that eats the first six hours |
| Two named submitters with platform access | An afternoon | Holiday and time zone cover for a calendar deadline |
| Early warning template | An hour | Five fields written calmly instead of at 3am |
| SBOM per shipped version | Build pipeline work | Answers "which products contain this component" in minutes |
| Customer notice template | An hour | Informing users is part of the duty where appropriate |
| A known coordinating CSIRT | The Article 18 mandate | Removes the routing question entirely |
| A rehearsal | Half a day | Every gap on this list surfaces in the first table-top exercise |
Companies that run one rehearsal before September 2026 will discover something uncomfortable and cheap. Companies that do not will discover the same thing during an actual exploitation, when it is neither.
The 24-hour message is an alert, not an analysis. It says what product, what is happening and whether it appears malicious.
Whether the issue affects users in other Member States, which is what triggers wider dissemination between CSIRTs.
You are expected to update it. Waiting for certainty is the mistake, not sending an incomplete first message.
Severity, impact and corrective measures where available. This is where the technical detail belongs.
For vulnerabilities, within 14 days of a corrective measure being available; for severe incidents, within a month.
Timestamps of awareness and submission. If a deadline is ever questioned, that record is the answer.
If it is in the product you placed on the market and it is being actively exploited, it is reportable. The licence of the dependency does not move the duty. This is precisely why the SBOM requirement exists: without it, working out which of your products contain the affected component takes longer than the deadline allows.
Becoming aware does not require your own detection. A credible customer report of exploitation starts the clock, which is why the definition of awareness needs to be written down before it is tested. Teams that leave it undefined lose hours arguing about whether a report was credible enough, and the clock does not pause for the discussion.
From 11 September 2026 the clock is 24 hours for the early warning, 72 for the notification, then a final report, submitted through ENISA's single platform to the CSIRT determined by where you are established or represented. Actively exploited is the trigger, not merely discovered. Write down what counts as becoming aware, name two submitters, draft the templates now, keep an SBOM so you can answer which products are affected, and if you have no establishment in the Union, sign the Article 18 mandate so the recipient is settled before the day you need it. One rehearsal before September will find every gap in this paragraph.
| Hour | Who | What |
|---|---|---|
| 0 | Security lead | Declares awareness against the written definition and starts the clock in the log |
| 0 to 2 | Engineering | Identifies affected products and versions from the SBOM |
| 2 to 6 | Named submitter | Drafts the early warning from the template and confirms the coordinating CSIRT |
| Before 24 | Named submitter | Submits through the single reporting platform and records the timestamp |
| 24 to 72 | Security lead | Severity, impact, corrective measures, then the notification |
| In parallel | Support and marketing | User communication where appropriate, from the pre-drafted template |
| After | Compliance | Final report, and the record of every timestamp |
Seven rows, one page, printed. That is the entire preparation, and the companies that have it treat 11 September 2026 as a date rather than an event.


11 September 2026. The rest of the regulation applies fully from 11 December 2027.
An early warning about an actively exploited vulnerability in your product, or a severe incident affecting the product's security.
Not unless it is actively exploited. Discovery alone does not start this clock, though it triggers your handling duties.
General information on the vulnerability or incident, its severity and impact, and corrective measures where available.
For vulnerabilities, within 14 days of a corrective measure being available. For severe incidents, within one month of the notification.
Through the single reporting platform established and maintained by ENISA, which routes to the coordinating CSIRT.
The one in your Member State of main establishment; failing that, of your authorised representative, then importer, then distributor.
No. The report requires facts only your team has, and the platform is designed for the manufacturer.
Where appropriate, yes: about the vulnerability or incident and any measures they can take.
The reporting obligations reach products made available on the market, including those placed before the full application date.
Both reports are due, to potentially different recipients. Decide in advance who writes which.
Calendar. Weekends and holidays included, which is why two named submitters matter.
Reporting failures fall within the regulation's penalty framework, with ceilings up to €15 million or 2.5% for the most serious breaches.
Yes. Any natural or legal person may notify vulnerabilities, threats, incidents and near misses on a voluntary basis.
Enormously. Knowing which products contain an affected component is what turns a 24-hour deadline into a manageable one.
Report on the basis of what you know and update. The early warning is deliberately short and is meant to be provisional.
It is optional, but without it the recipient of your report is determined further down a chain you may not control.
Within 24 hours of a short intake call, well before the September 2026 date.
Related: the Article 18 mandate · how it differs from NIS2
Europe Services, SE in Prague as your Article 18 representative, so the coordinating CSIRT is known in advance and written into your runbook.
Request this service