Stavenor

Guides

CRA Article 14: The 24-Hour Early Warning, Field by Field

Updated 20 September 20265 min read

Since 11 September 2026, every manufacturer of a product with digital elements sold in the EU must report two kinds of event under Article 14 of the Cyber Resilience Act (Regulation (EU) 2024/2847):

The first filing — the early warning — is due within 24 hours of the manufacturer becoming aware. This page explains when that clock starts, what ENISA's Single Reporting Platform actually requires in those 24 hours, and the three traps that catch manufacturers out.


When does the 24-hour clock start?

Not at detection. Not when management signs off. At awareness.

The European Commission's guidance on the application of the CRA (document C(2026) 5252, paragraphs 213–214) sets the test. When a suspicious event is detected, or a third party reports a potential vulnerability or incident, the manufacturer should assess it immediately. It is regarded as having become aware when, after that initial assessment, it has a reasonable degree of certainty that:

The guidance adds that the emphasis should be on prompt action to carry out the initial assessment. You cannot hold awareness back by holding the assessment back.

Practical rule: record two timestamps for every event — when it was detected, and when the initial assessment concluded. The distance between them is the first thing an authority will look at.


The four deadlines — and a fifth filing

Filing Deadline Runs from
Early warning 24 hours Awareness
Notification 72 hours Awareness
Final report — vulnerability 14 days A corrective or mitigating measure becoming available
Final report — severe incident 1 month Submission of the 72-hour notification

Note that the two final-report clocks have different triggers. They belong in your runbook as two separate paths.

And there is a filing most summaries leave out: under Article 14(6), the coordinating CSIRT may request an intermediate report on status updates at any time. The Regulation sets no deadline for it — the CSIRT does.


What the platform asks for at 24 hours

This is where most runbooks are wrong. The early warning is often described as a short alert, with the substance deferred to the 72-hour notification. ENISA's own CRA SRP Glossary (version 1.3, 10 September 2026) says otherwise.

Required at the early warning — actively exploited vulnerability (8 fields):

Field Limit
Notification type
Title 255 characters
Summary 4,000 characters
Manufacturer name system-generated
Member States where the product is available
Product name 255 characters
Product version 255 characters
Date and time you became aware

Severe incident (9 fields): the same seven common fields, plus the awareness date and time, plus whether the incident is suspected of being caused by unlawful or malicious acts (Yes / No / Unknown).

The Member States field is not just a platform convenience: the Regulation itself requires it at the early warning stage, where applicable (Article 14(2)(a) and 14(4)(a)).


Three traps

1. The Summary is required at 24 hours

Up to 4,000 characters covering what happened, the affected product or version, the known impact and the current mitigation status. If your procedure assumes you will write this at hour 70, you have already lost two days. Draft it in advance, outside the platform.

2. The awareness field may not be on screen

In the Glossary, the awareness timestamp for a vulnerability is marked required — with ENISA's own footnote that the field will arrive in a later release of the platform. For incidents, the field is currently labelled "date and time when the incident was detected". Detection is not awareness. Keep your own timestamped record. If an authority asks why your early warning arrived when it did, that record is your evidence — not the platform.

3. The on-screen 72-hour counter is not your deadline

ENISA's FAQ confirms that the platform's 72-hour counter shows a due date 48 hours after the early warning is submitted — not 72 hours after awareness. A filing can show as overdue before the legal deadline has passed, or look comfortable when it is not. Keep your own clock.


Who can file


Two scope points people miss

Your installed base is in scope. Article 69(3) applies the reporting obligations to every in-scope product placed on the market before 11 December 2027 — including products you sold before the CRA's other obligations apply.

Reporting outlives support. The Commission's guidance (paragraph 210) is explicit: vulnerability handling obligations end with the support period; reporting obligations do not.


Sources

Position as at 20 September 2026. ENISA updates its platform guidance frequently. This page is general information, not legal advice.