
Article 14 · Regulation (EU) 2024/2847 · Reporting from 11 September 2026
Article 14 applies in —
From 11 September 2026 every manufacturer of a product with digital elements sold in the European Union must send an early warning within 24 hours of becoming aware, a full notification within 72, and a final report within 14 days. The clock does not pause at night, at the weekend or in August. We hold it for you, in Europe, all year.
Europe Services, SE — Prague, Czech Republic. Active since 2018. Article 27, Article 16 and CRA mandates already signed for companies in 24 countries.
A simulation. The real deadlines run in calendar hours, not working hours.
The duty falls on the manufacturer of the product, wherever it is established. Not on the importer, not on the distributor, not on the customer who found the flaw. If you sell anything that connects — an app, a router, a camera, a machine with firmware, a piece of software — and it reaches a buyer in the European Union, you are the one holding the clock.
| Situation | Who reports | What we do |
|---|---|---|
| Manufacturer outside the EU, sells directly to EU buyers | You. The CSIRT is determined through your authorised representative, then the importer, then the distributor. | We are the representative and we file for you. |
| Manufacturer in the EU | You, to the CSIRT of the member state of your main establishment. | We run the intake channel and prepare the filing. |
| Open source steward, non-commercial | Lighter regime, but the duty to report an exploited vulnerability still applies. | Reduced plan, same channel. |
| Product already on the market before the CRA applied | You. Legacy products are inside the reporting duty from day one. | We map the legacy catalogue with you. |
| Importer or distributor | Not you, unless you put the product on the market under your own name. | We tell you honestly that you do not need us. |

Not every bug is reportable. Two events are, and mixing them up is the most expensive mistake a manufacturer can make in September.
Someone is using the flaw against your product, right now, and you have evidence of it. Proof of concept published, exploitation seen in the field, a customer reporting a compromise. A vulnerability nobody is exploiting is not reportable under Article 14, however severe its score.
An event that affects the security of the product itself: your build system compromised, a malicious update signed and shipped, a repository poisoned. The damage does not have to be realised — the impact on the product's security is enough.
The clock starts when you become aware. Unverified noise does not start it; a credible report does. Deciding where that line sits, in writing, before the event, is half of what we sell.
Most of what is being sold this month as "CRA compliance" is not due yet. We would rather tell you now than take money for it.
Article 14 only: the early warning, the notification, the final report, and informing affected users. Filed through the single reporting platform run by ENISA, reaching your coordinating CSIRT at the same time.
The coordinated disclosure policy, the software bill of materials, secure-by-design requirements, the declared support period, CE marking and conformity assessment. Useful to start now, not yet enforceable — and anyone telling you otherwise is selling urgency.
The catch is practical rather than legal: you cannot report what you never detect. A manufacturer with no intake channel does not become aware of an exploited vulnerability until a journalist calls. That is why the channel, and not the paperwork, is the thing worth buying in 2026.
A published address that nobody reads is worse than no address, because it proves you were told. Ours is staffed continuously — nights, weekends, the whole of August, 25 December — and every message that arrives is answered, logged and triaged inside the first hours.
A reporting address in your own name, published on your site and in your security.txt, pointing at our desk. Researchers, customers and supply-chain partners write there instead of nowhere.
Every report is acknowledged, deduplicated and rated against one question: is there evidence of active exploitation? If yes, your named contacts are woken up. If no, it goes on the log and you read it on Monday.
We prepare the early warning, the 72-hour notification and the final report in the format the platform expects, in English, and send them once you confirm the facts. You approve; we file.
Every message in, every decision, every filing, kept with its exact time. If an authority asks in 2029 what you knew and when, the answer is a document, not a memory.
For a manufacturer outside the Union, the competent CSIRT is determined first by the authorised representative. Because we hold that mandate, your coordinating authority is known before anything happens, not decided in a panic.
The regulation asks you to tell affected users, without a fixed deadline and without a prescribed format. We draft that notice with you, so it does not become the second incident.
Wider than people expect. Any software or hardware product whose intended use includes a data connection, direct or indirect, to a device or network. A mobile app. A desktop program. A router, a camera, a smart plug, a fitness band. An industrial machine with a controller. A component sold separately.
Outside: medical devices, cars, aviation and marine equipment, products regulated for national security, and software as a service unless it forms part of the remote data processing of a covered product. If you are not sure which side you sit on, that is the first question we answer, free, before you pay anything.
| Deadline | From | What has to be in it | Who receives it |
|---|---|---|---|
| 24h | Becoming aware | Early warning: that it exists, whether it is being exploited, which member states may be affected. Facts you have, not an analysis. | Coordinating CSIRT and ENISA |
| 72h | Becoming aware | Notification: general information on the product, the nature of the flaw, the severity and impact, and any corrective measures already taken or available. | Coordinating CSIRT and ENISA |
| 14d | A fix being available | Final report on an exploited vulnerability: description, severity, impact, and the corrective or mitigating measures now available to users. | Coordinating CSIRT and ENISA |
| 1m | The 72-hour notification | Final report on a severe incident: what happened, how, the cross-border effect, the measures applied. | Coordinating CSIRT and ENISA |
Plus, without a fixed deadline: informing the users of the affected product, and where relevant telling them what they can do themselves. Late is not the only failure mode — a filing that contradicts what you publish is worse.
Companies routinely believe one filing covers all of them. It does not, and the deadlines are not the same.
| CRA | NIS2 | GDPR | |
|---|---|---|---|
| Who is bound | Manufacturer of the product | Operator of the service | Controller of the data |
| What triggers it | Exploited vulnerability or severe incident affecting product security | Incident with significant impact on the service | Breach of personal data |
| First deadline | 24h | 24h | 72h |
| Filed with | CSIRT and ENISA, single platform | National CSIRT or authority | Data protection authority |
| Applies from | 11 September 2026 | In force | In force |
One event can trigger two of them at once. A signed malicious update that also exposes customer records is a CRA severe incident and a personal data breach, on two clocks, to two authorities, with two different sets of words. We hold the CRA clock, and we tell you when the other one has started.
Failing to report sits in the highest penalty band of the regulation, alongside the essential cybersecurity requirements themselves. Fines scale with worldwide turnover, and market surveillance authorities can order a product withdrawn or recalled from the Union market.
The commercial damage arrives sooner than the fine. A withdrawal order reaches your distributors and marketplaces in days, and an unanswered researcher publishes on the fifteenth day because nobody wrote back.
Three moments of the same duty: the report arriving, the filing being written, and the product it is about.



One price, one renewal, no hourly billing and no charge per product. A single provider quotes five figures a year for the same duty; the desk costs less than one hour of the incident it prevents.
CHANNEL
€390 / year
Renewal €320
One product line
CHANNEL + FILING
€690 / year
Renewal €590
Whole catalogue, legacy included
REPRESENTATIVE
€1190 / year
Renewal €990
Manufacturers outside the Union
We do not sell penetration tests, CE certification, SBOM tooling or conformity assessment. When you need those, we say so and stay out of the way.
We have been tracking these dates since the text was adopted, and revising this page each time they moved. Two of them already have.
| Date | Milestone | What changed |
|---|---|---|
| 2024-10-23 | Adoption | Regulation (EU) 2024/2847 adopted. The text is final; the dates are not all the same. |
| 2024-12-10 | Entry into force | The regulation enters into force. Nothing is enforceable yet, and this is where most compliance calendars quietly stop. |
| 2026-06-11 | Notified bodies | Articles 35 to 51 apply: conformity assessment bodies can be notified. Relevant to certification providers, not yet to manufacturers. |
| 2026-09-11 ← | Article 14 · reporting | Actively exploited vulnerabilities and severe incidents become reportable. 24 hours, 72 hours, 14 days. Legacy products included. |
| 2027-12-11 | Everything else | Essential requirements, vulnerability handling, disclosure policy, SBOM, support period, CE marking, market surveillance. |
Most of the arguments about this regulation are arguments about four or five definitions. These are the ones that decide whether you file or not.
Everything on this page comes from the regulation itself. Where we interpret, we say so. Where we are unsure, we say that too.
The consolidated text on EUR-Lex, in all official languages.
The European Commission page on what must be reported from 11 September 2026.
How the early warning is written and what goes in it.
What the mandate covers and who determines your CSIRT.
Two 24-hour duties, two different triggers.
Where the scope starts and stops.
Page maintained continuously since the regulation entered into force. Last revision: 02 September 2026. When a date moves, this page moves with it, and the old date stays visible in the table above.
Tell us what you sell and where. We answer with the one thing you need to know first: whether the CRA reaches you at all, and which authority would receive your filing. That answer is free and it does not commit you to anything.
Annual fee, paid in advance. You can cancel before each renewal.
From the second year the renewal is lower: 320, 590 and 990 euro a year.
Where is the manufacturer established?
No VAT for customers outside the EU. Inside the EU with a valid VAT number: reverse charge.
Tell us what you manufacture and where it is sold. We answer with whether the CRA reaches you at all.
We reply within one business day, in your language. No sales sequence, no newsletter.
One working day for an answer. No payment at this step.