CRA Article 14: The 24-Hour Early Warning, Field by Field
Updated 20 September 20265 min read
Since 11 September 2026, every manufacturer of a product with digital elements sold in the EU must report two kinds of event under Article 14 of the Cyber Resilience Act (Regulation (EU) 2024/2847):
- an actively exploited vulnerability in its product, and
- a severe incident having an impact on the security of its product.
The first filing — the early warning — is due within 24 hours of the manufacturer becoming aware. This page explains when that clock starts, what ENISA's Single Reporting Platform actually requires in those 24 hours, and the three traps that catch manufacturers out.
When does the 24-hour clock start?
Not at detection. Not when management signs off. At awareness.
The European Commission's guidance on the application of the CRA (document C(2026) 5252, paragraphs 213–214) sets the test. When a suspicious event is detected, or a third party reports a potential vulnerability or incident, the manufacturer should assess it immediately. It is regarded as having become aware when, after that initial assessment, it has a reasonable degree of certainty that:
- a vulnerability in its product is being actively exploited, or
- a severe incident has occurred and has compromised the security of its product.
The guidance adds that the emphasis should be on prompt action to carry out the initial assessment. You cannot hold awareness back by holding the assessment back.
Practical rule: record two timestamps for every event — when it was detected, and when the initial assessment concluded. The distance between them is the first thing an authority will look at.
The four deadlines — and a fifth filing
| Filing | Deadline | Runs from |
|---|---|---|
| Early warning | 24 hours | Awareness |
| Notification | 72 hours | Awareness |
| Final report — vulnerability | 14 days | A corrective or mitigating measure becoming available |
| Final report — severe incident | 1 month | Submission of the 72-hour notification |
Note that the two final-report clocks have different triggers. They belong in your runbook as two separate paths.
And there is a filing most summaries leave out: under Article 14(6), the coordinating CSIRT may request an intermediate report on status updates at any time. The Regulation sets no deadline for it — the CSIRT does.
What the platform asks for at 24 hours
This is where most runbooks are wrong. The early warning is often described as a short alert, with the substance deferred to the 72-hour notification. ENISA's own CRA SRP Glossary (version 1.3, 10 September 2026) says otherwise.
Required at the early warning — actively exploited vulnerability (8 fields):
| Field | Limit |
|---|---|
| Notification type | — |
| Title | 255 characters |
| Summary | 4,000 characters |
| Manufacturer name | system-generated |
| Member States where the product is available | — |
| Product name | 255 characters |
| Product version | 255 characters |
| Date and time you became aware | — |
Severe incident (9 fields): the same seven common fields, plus the awareness date and time, plus whether the incident is suspected of being caused by unlawful or malicious acts (Yes / No / Unknown).
The Member States field is not just a platform convenience: the Regulation itself requires it at the early warning stage, where applicable (Article 14(2)(a) and 14(4)(a)).
Three traps
1. The Summary is required at 24 hours
Up to 4,000 characters covering what happened, the affected product or version, the known impact and the current mitigation status. If your procedure assumes you will write this at hour 70, you have already lost two days. Draft it in advance, outside the platform.
2. The awareness field may not be on screen
In the Glossary, the awareness timestamp for a vulnerability is marked required — with ENISA's own footnote that the field will arrive in a later release of the platform. For incidents, the field is currently labelled "date and time when the incident was detected". Detection is not awareness. Keep your own timestamped record. If an authority asks why your early warning arrived when it did, that record is your evidence — not the platform.
3. The on-screen 72-hour counter is not your deadline
ENISA's FAQ confirms that the platform's 72-hour counter shows a due date 48 hours after the early warning is submitted — not 72 hours after awareness. A filing can show as overdue before the legal deadline has passed, or look comfortable when it is not. Keep your own clock.
Who can file
- Each manufacturer has one Primary AR (Assigned Representative) and can add up to 20 Secondary ARs. On screen, a Secondary AR's system role is displayed as "AR Backup User".
- A Primary AR must hold a verified manufacturer association before it can invite Secondary ARs. Start early: this step is gated by the CSIRT.
- An invited Secondary AR must complete registration within 7 days, or the invitation expires.
- All ARs of a manufacturer can view and update its submitted notifications. Drafts are the exception — they sit in the individual AR's account. Draft in a shared document, then transcribe.
Two scope points people miss
Your installed base is in scope. Article 69(3) applies the reporting obligations to every in-scope product placed on the market before 11 December 2027 — including products you sold before the CRA's other obligations apply.
Reporting outlives support. The Commission's guidance (paragraph 210) is explicit: vulnerability handling obligations end with the support period; reporting obligations do not.
Sources
- Regulation (EU) 2024/2847 (Cyber Resilience Act), Articles 14, 69 and 71 — Official Journal of the European Union
- ENISA, CRA SRP Glossary, version 1.3, 10 September 2026
- ENISA, Single Reporting Platform — Frequently Asked Questions, updated 17 September 2026
- ENISA, CRA SRP Guidance — AR User Registration
- European Commission, Guidance on the application of the Cyber Resilience Act, C(2026) 5252, paragraphs 210 and 213–214
Position as at 20 September 2026. ENISA updates its platform guidance frequently. This page is general information, not legal advice.