Article 14 Reporting Readiness
Article 14 reporting readiness is the preparation needed before the first mandatory reporting date on 11 September 2026. It is separate from deciding whether a specific vulnerability or incident is reportable.
Readiness before a report
A manufacturer cannot wait for an incident to learn the reporting route. Before Article 14 applies, the manufacturer should know which products may be in scope, who can submit a report, which CSIRT endpoint will be used, and in which Member States the product has been available.
Route
Reports go through the CRA Single Reporting Platform.
Coordinator
The first endpoint is tied to the coordinating CSIRT.
Member States
The report can need the Member States where the product has been made available.
Product facts
Product name, version, type, exploit or incident facts, and mitigation status must be available quickly.
Coordinating CSIRT
The notification shall be submitted using the electronic notification end-point of the CSIRT designated as coordinator of the Member State where the manufacturers have their main establishment in the Union and shall be simultaneously accessible to ENISA.
Regulation (EU) 2024/2847, Article 14(7)
For an EU manufacturer, the main establishment is the Member State where cybersecurity decisions for the product are mainly taken. If that cannot be determined, the fallback is the Member State where the manufacturer has its Union establishment with the highest number of employees.
For a manufacturer with no main establishment in the Union, Article 14(7) uses an order based on the authorised representative, importer, and distributor connected with the highest number of the manufacturer's products.
Member State product map
The 24-hour early warning asks for Member States where the manufacturer is aware that the affected product has been made available. The SRP also routes information to other CSIRTs for Member States where the product is available.
- direct sales and distributor channels in the EU;
- marketplaces, app stores, and download channels used for EU users;
- importers and distributors that place or make the product available in specific Member States;
- product versions, firmware releases, cloud-dependent functions, or model variants that affect the report.
Report data readiness
ENISA describes the SRP as a single entry point. The manufacturer submits once, and the platform routes the notification to the coordinating CSIRT and ENISA. The report still depends on internal product and security data being ready.
- who is authorised to submit the notification;
- which product, version, component, or service function is affected;
- whether the event is treated as an actively exploited vulnerability or a severe incident;
- what is known, what is still being investigated, and what mitigation is available;
- which users or Member States may be affected;
- how the manufacturer will inform impacted users when Article 14 requires it.
Boundary with the trigger page
This page is about readiness. The legal trigger for a mandatory report is explained in Vulnerability Reporting. A manufacturer needs both: a process that can recognise reportable events and a reporting setup that can meet the 24-hour and 72-hour deadlines.
Readiness is not over-reporting
Preparing the SRP route and product data does not mean every vulnerability is reportable. The Article 14 trigger still has to be met.