Stavenor

Guides

CRA Article 14(6): The Intermediate Report Nobody Plans For

Updated 20 September 20262 min read

Most guides to Cyber Resilience Act reporting describe three filings: the early warning, the notification and the final report. ENISA's platform is built around the same three stages.

There is a fourth possible filing, and almost nobody plans for it.


What Article 14(6) says

Where necessary, the CSIRT designated as coordinator that initially received the notification may request an intermediate report on relevant status updates about the actively exploited vulnerability or the severe incident.

Two things follow from the text:


Why it catches manufacturers out

The case does not close at 72 hours. Many internal procedures treat the 72-hour notification as the end of the urgent phase and hand the file back to engineering. If the CSIRT then asks for an update, nobody is ready to answer it.

The request may arrive at any time. Requests and alerts from CSIRTs arrive through the platform. If nobody is watching at the weekend, a request with a deadline attached can go unseen.


What to prepare in advance

A short, pre-structured status update covering:

Watch the fix date. For an actively exploited vulnerability, the 14-day final-report clock runs from the date a corrective or mitigating measure became available. If that date has passed by the time you write the intermediate report, the final-report clock is already running.


Three operational rules

  1. Name someone responsible for answering an intermediate-report request, including outside working hours.
  2. Put a monitored team mailbox behind every representative account on the platform.
  3. Log the request and your response in the same register as the other filings.

Nothing in Article 14 suggests that an intermediate report resets, extends or pauses any other deadline. Plan as though it does not.

Sources

Position as at 20 September 2026. General information, not legal advice.