When Does a Manufacturer "Become Aware" Under the CRA?
Updated 20 September 20263 min read
Every Article 14 reporting deadline under the Cyber Resilience Act — the 24-hour early warning and the 72-hour notification — runs from one moment: when the manufacturer becomes aware of an actively exploited vulnerability or a severe incident.
Get that moment wrong, and every deadline after it is wrong too.
The Commission's definition
The European Commission's guidance on the application of the CRA (C(2026) 5252, paragraphs 213–214) sets it out:
- When a suspicious event is detected, or a third party brings a potential vulnerability or incident to the manufacturer's attention, the manufacturer should assess it immediately.
- The manufacturer is regarded as having become aware when, after that initial assessment, it has a reasonable degree of certainty that: - a vulnerability in its product is being actively exploited; or - a severe incident has occurred and has led to the security of its product being compromised.
- The emphasis should be on prompt action to carry out the initial assessment.
The loophole that is closed
Because awareness follows the initial assessment, it might seem that a slow assessment buys time. It does not. The guidance puts the emphasis on prompt action to carry out that assessment. You cannot hold awareness back by holding the assessment back.
Detection is not awareness
Two moments, often hours apart:
| Moment | What it is |
|---|---|
| Detection | A signal arrives: an alert, a researcher's email, a supplier advisory |
| Awareness | The initial assessment concludes, with reasonable certainty, that the event is reportable |
The clock runs from awareness. But the gap between the two is the first thing an authority will look at — so record both, with the name of the person who made the assessment and the evidence relied on.
The platform will not record it for you
ENISA's CRA SRP Glossary (version 1.3):
- for a vulnerability, the awareness field is marked required at 24 hours — but ENISA's own footnote says it will arrive in a later release of the platform;
- for an incident, the field is currently labelled "date and time when the incident was detected".
Your own timestamped record is your evidence.
A familiar concept, if you already handle data breaches
Paragraph 212 of the guidance aligns the CRA concept of becoming aware with recital 31 of Implementing Regulation (EU) 2024/2690 under NIS2, and with the European Data Protection Board's Guidelines 9/2022 on personal data breach notification. If your organisation already runs a GDPR breach process, the awareness logic is the same one.
Write the definition down before you need it
A workable internal definition, consistent with the guidance:
The organisation is aware of a potentially reportable event when an initial assessment, performed without delay by a named competent person, concludes with a reasonable degree of certainty that a vulnerability in a product placed on the market is being actively exploited, or that a severe incident affecting its security has occurred. The conclusion is recorded with date, time, assessor and evidence.
Sources
- European Commission, Guidance on the application of the CRA, C(2026) 5252, paragraphs 212–214
- ENISA, CRA SRP Glossary, version 1.3, 10 September 2026
- Regulation (EU) 2024/2847, Article 14
Position as at 20 September 2026. General information, not legal advice.