EU's Cyber Resilience Act Article 14 kicks in: 24-hour clock for exploited vulnerabilities
Since 11 September 2026, Article 14 of the EU Cyber Resilience Act (Regulation (EU) 2024/2847) requires manufacturers to report actively exploited vulnerabilities and severe incidents. Deadlines are 24 hours for an early warning, 72 hours for a fuller notification and 14 days for a final report; penalties of up to €15 million or 2.5% of turnover only arrive in December 2027.
- Article 14 of the CRA applies from 11 September 2026; the rest of the regulation follows on 11 December 2027
- Early warning within 24 hours, notification within 72 hours, final report within 14 days of a fix
- Reports go through ENISA's CRA Single Reporting Platform to the coordinating CSIRT
- Penalties of up to €15 million or 2.5% of global turnover start in December 2027
Read next
Policy