漏洞报告
Article 14 报告义务在 manufacturer 发现两类事件时触发:产品中存在 actively exploited vulnerability,或发生影响产品安全的 severe incident。该义务自 2026 年 9 月 11 日起适用,也适用于 CRA 全面适用前已经投放市场的适用范围内产品。
报告触发条件
触发条件不是产品类别、CVSS 分数,也不是漏洞存在这个事实本身。Article 14 关注 manufacturer 是否已经 aware of 某个 product with digital elements 中的可报告事件。
Actively exploited vulnerability
漏洞必须存在于产品中,并且有可靠证据显示恶意利用已经发生。
Severe product-security incident
事件必须对 product with digital elements 的安全产生严重影响。
其他漏洞、网络威胁、未遂事件和低影响事件仍可能影响漏洞处理或自愿报告,但它们不会自动成为强制 Article 14 报告。
Actively exploited vulnerability
‘actively exploited vulnerability’ means a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner;
Regulation (EU) 2024/2847, Article 3(42)
这个定义包含三个要素:存在漏洞;有可靠证据证明漏洞被利用;利用行为是恶意且未获系统所有者许可。理论利用路径或扫描器结果本身通常不够。
Zero-day 漏洞可能触发报告,但只有在 manufacturer 拥有可靠证据,证明恶意主体已经利用该漏洞时才触发。善意漏洞赏金报告或实验室发现,如果没有此前恶意利用证据,不属于强制 Article 14 触发条件。
可靠认知可能来自以下渠道:
- 客户或合作方报告入侵,并提供产品漏洞被利用的证据;
- 政府机构、安全研究人员或威胁情报报告指出产品中存在被利用情况;
- manufacturer 自身遥测、监控或调查发现利用证据。
漏洞还必须 contained in the product with digital elements。一个集成组件在其他地方受影响,并不自动意味着该漏洞也在 manufacturer 的产品中构成 actively exploited vulnerability。
影响产品安全的严重事件
Severe incident 也是以产品为中心。一般公司 IT 事件本身不够;事件必须影响 product with digital elements 的安全。
Article 14 下的 severe incident 通常落入两类:
- 已经或可能负面影响产品保护敏感或重要数据、功能的可用性、真实性、完整性或保密性的能力;
- 已经或可能导致恶意代码被引入或执行于产品,或用户的 network and information systems。
发布链路很重要
构建、更新或发布链路被攻破,并可能让恶意代码到达产品或用户时,可能构成 severe incident。
24 小时、72 小时和最终报告
Article 14 使用分阶段报告。第一阶段是 early warning,不要求完整技术卷宗。后续阶段随着调查和缓解推进,补充可获得的信息。
- Early warning:manufacturer aware 后,无不当延迟且最迟 24 小时内。
- Main notification:aware 后,无不当延迟且最迟 72 小时内,除非相关信息已经提供。
- Actively exploited vulnerability 的 final report:纠正或缓解措施可用后最迟 14 天内。
- Severe incident 的 final report:72 小时 incident notification 后 1 个月内。
期限从 manufacturer aware of 可报告事件开始计算。24 小时和 72 小时不是等待期;法规仍要求 without undue delay。
Single Reporting Platform
For the purposes of the notifications referred to in Article 14(1) and (3) and Article 15(1) and (2) and in order to simplify the reporting obligations of manufacturers, a single reporting platform shall be established by ENISA. The day-to-day operations of that single reporting platform shall be managed and maintained by ENISA. The architecture of the single reporting platform shall allow Member States and ENISA to put in place their own electronic notification end-points.
Regulation (EU) 2024/2847, Article 16(1)
Single Reporting Platform 是 Article 14 通知的提交路径。该平台计划在 2026 年 9 月 11 日前投入运行,并在此前开展测试。
一次提交,受控共享
Manufacturer 通过平台向 coordinating CSIRT 和 ENISA 报告。接收的 CSIRT 随后向其他相关 CSIRT 共享通知,除非存在正当例外导致共享延迟。
报告准备
触发条件和报告准备不是同一件事。本页说明何时触发 Article 14。单独的准备页面解释 SRP 路径、coordinating CSIRT、成员国产品地图,以及 2026 年 9 月 11 日前应准备的内部数据。
触发规则清楚后,可继续阅读 Article 14 报告准备 。
边界情况
没有补丁不是 Article 14 的判断标准。Zero-day 在 manufacturer 拥有可靠证据证明恶意主体已经利用时,才成为强制报告。
如果 actively exploited vulnerability 存在于成品中,成品 manufacturer 需要报告。如果该组件本身也被单独投放市场,组件 manufacturer 也可能有义务。
Article 14 报告义务自 2026 年 9 月 11 日起适用于 CRA 适用范围内产品,包括 2027 年 12 月 11 日前已经投放市场的产品。义务在 reporting duties 开始适用后,manufacturer aware of 可报告事件时触发。
Article 14 还要求 manufacturer 通知受影响用户,并在适当时通知所有用户,说明漏洞或事件以及用户可部署的缓解措施。Article 15 是强制 Article 14 触发条件之外的自愿报告路径。