CRA Severe Incident: The Two Tests of Article 14(5)
Updated 20 September 20263 min read
Under Article 14 of the Cyber Resilience Act, manufacturers must report severe incidents having an impact on the security of their product — early warning within 24 hours, notification within 72. Whether an incident is "severe" decides whether that clock runs at all.
Article 14(5) answers the question with two alternative tests. Meeting either one is enough.
The two tests
An incident is severe where:
(a) it negatively affects, or is capable of negatively affecting, the ability of the product to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions; or
(b) it has led, or is capable of leading, to the introduction or execution of malicious code in the product, or in the network and information systems of a user of the product.
What most summaries get wrong
Test (b) is usually missing. Many published summaries — including the paraphrase in ENISA's own FAQ — describe only something close to test (a). But a manufacturer that checks only (a) can wrongly conclude an incident is not reportable.
Test (a) is qualified. It concerns sensitive or important data or functions, not all data. Summaries that drop the qualifier make the test look broader than it is.
When a summary and the binding text differ, the text applies.
What test (b) looks like in practice
The textbook case is an incident in the manufacturer's own development or distribution chain: malicious code introduced into the channel through which security updates are shipped. The product may never have been attacked directly in the field — but the incident is capable of leading to malicious code executing on users' devices.
That is why the incident-reporting stream exists alongside the vulnerability stream: it captures compromises of the process, not only flaws in the product.
What is usually not reportable
- A known vulnerability with no indicators of active exploitation — that belongs to vulnerability handling, not incident reporting.
- A repelled intrusion attempt that did not affect the product's security properties.
- A service outage with no cybersecurity relevance.
- Vulnerabilities discovered in good faith, for testing, investigation, correction or disclosure — recital 68 states these are not subject to mandatory notification.
Record the negative decisions too. A register that shows only the incidents you reported does not demonstrate an assessment process. One that also records what you assessed and set aside, with reasons, does.
Once you decide it is severe
The clock runs from the moment you became aware — see when a manufacturer becomes aware. The early warning must state whether the incident is suspected of being caused by unlawful or malicious acts, and the final report is due one month after the 72-hour notification.
Sources
- Regulation (EU) 2024/2847, Article 14(4), 14(5) and recital 68 — Official Journal of the European Union
- ENISA, Single Reporting Platform — FAQ, updated 17 September 2026
Position as at 20 September 2026. General information, not legal advice.