Article 14 报告准备
Article 14 reporting readiness 是 2026 年 9 月 11 日首个强制报告日期前所需的准备。它不同于判断某个具体漏洞或事件是否可报告。
报告前准备
Manufacturer 不能等到事件发生才学习报告路径。在 Article 14 适用前,manufacturer 应知道哪些产品可能在范围内、谁能提交报告、将使用哪个 CSIRT endpoint,以及产品已经在哪些 Member States 被 made available。
路径
报告通过 CRA Single Reporting Platform 提交。
协调方
第一个 endpoint 与 coordinating CSIRT 相关。
Member States
报告可能需要列出产品已经 made available 的 Member States。
产品事实
产品名称、版本、类型、利用或事件事实,以及缓解状态必须能快速取得。
Coordinating CSIRT
The notification shall be submitted using the electronic notification end-point of the CSIRT designated as coordinator of the Member State where the manufacturers have their main establishment in the Union and shall be simultaneously accessible to ENISA.
Regulation (EU) 2024/2847, Article 14(7)
对 EU manufacturer 来说,main establishment 是主要作出产品网络安全决策的 Member State。如果无法确定,fallback 是 manufacturer 在 Union 内员工人数最多的 establishment 所在 Member State。
对在 Union 内没有 main establishment 的 manufacturer,Article 14(7) 使用一个基于 authorised representative、importer 和 distributor 的顺序,并连接到该 manufacturer 产品数量最多的主体。
Member State 产品地图
24 小时 early warning 要求列出 manufacturer 知道受影响产品已经 made available 的 Member States。SRP 也会把信息路由到产品可用 Member States 的其他 CSIRTs。
- 欧盟内的直销和分销渠道;
- 面向欧盟用户使用的 marketplaces、app stores 和下载渠道;
- 在特定 Member States placing 或 making the product available 的 importers 和 distributors;
- 影响报告的产品版本、firmware releases、依赖云的功能或型号变体。
报告数据准备
ENISA 将 SRP 描述为 single entry point。Manufacturer 提交一次,平台把通知路由给 coordinating CSIRT 和 ENISA。报告仍依赖内部产品和安全数据已经准备好。
- 谁被授权提交 notification;
- 哪个产品、版本、组件或服务功能受到影响;
- 事件被视为 actively exploited vulnerability 还是 severe incident;
- 已经知道什么,仍在调查什么,以及有哪些 mitigation 可用;
- 哪些用户或 Member States 可能受到影响;
- Article 14 要求时,manufacturer 将如何通知受影响用户。
与触发条件页面的边界
本页讨论 readiness。强制报告的法律触发条件见 Vulnerability Reporting。Manufacturer 需要两者:能识别可报告事件的流程,以及能满足 24 小时和 72 小时期限的报告设置。
Readiness 不是过度报告
准备 SRP 路径和产品数据,不表示每个漏洞都可报告。Article 14 触发条件仍必须被满足。