Why a reporting desk.

The obligation is not to be secure. It is to notice within 24 hours, tell ENISA, and be able to show afterwards what you knew and when. That is a different job from securing a product, and it is the job this page is about.

What Article 14 requires

Since 11 September 2026, a manufacturer who becomes aware of an actively exploited vulnerability in a product with digital elements must report it, including for products already on the market. Three stages, each with a clock that runs on weekends and holidays.

Early warning

within 24 hours

What the vulnerability is, which product it affects, and that you are looking into it. ENISA and your national CSIRT receive it.

Vulnerability notification

within 72 hours

What you know by then: severity, what you have done, and what users should do.

Final report

within 14 days of a fix

The vulnerability, the fix or mitigation, and how it reached the people who need it.

What "actively exploited" means

Not every vulnerability starts a clock. The obligation is about vulnerabilities that somebody is using against real systems. Two public sources say which those are, and both are read every hour here.

CISA KEV

The US catalogue of known exploited vulnerabilities: the list most of the industry treats as the definition of "being used".

ENISA EUVD

The European vulnerability database, with its own exploited list, published by the authority that receives your report.

Why watching by hand fails

Every team that tries it discovers the same four things, usually on a Saturday.

  • Volume. Tens of thousands of advisories a year, and your product is a few hundred components of other people’s code.
  • Timing. The clock starts when you become aware, not when you come back to work. A Friday evening entry leaves you until Saturday evening.
  • People. The person who reads the mailing list is on holiday, has left, or is in a meeting. An alert nobody acknowledges is an alert that did not happen.
  • Proof. Six months later you have to show what you knew and when. A mailbox is not a record, and neither is a spreadsheet anyone can edit.

What a reporting desk does

It is not a scanner and not a security product. It is the desk that keeps the obligation moving while you get on with fixing things.

  • Watches every component of every product against the exploited lists, every hour.
  • Opens a case the moment one of them is named, and starts the clocks.
  • Alerts a named person, and a second one if the first does not react.
  • Drafts each report from what it knows, ready for you to submit on ENISA’s platform.
  • Keeps an append-only record of what happened and when, which is the part that matters afterwards.
  • Says what it cannot see, rather than reporting a clean result it cannot stand behind.
The findings page of a product: how many components are monitored, which are not and why, and the vulnerabilities found in them.
Coverage, stated plainly: what is watched, what is not, and why.

Nothing in these pictures belongs to a customer: they are taken from our demonstration account, which is why the banner says so.

Ten questions to answer before you need the answers

If you can answer these ten, you are ready. If not, each one is a small piece of work now and a bad hour later.

  1. Do you have a current bill of materials for every product you place on the EU market?
  2. Is it generated by the build that ships, rather than written by hand?
  3. Do you know which of your components are watched by a source that says when one is being exploited?
  4. Is there a named person who receives an alert, and a second one behind them?
  5. Do those two know that a 24-hour clock starts when the alert arrives, weekend or not?
  6. Can you reach the person who decides, outside office hours?
  7. Do you know who submits to ENISA’s Single Reporting Platform, and do they have an EU Login?
  8. Have you written the early warning once, as a drill, before it is real?
  9. Can you show, six months later, when you became aware and what you did?
  10. Does your record survive the person who kept it leaving the company?

Want it on paper for the meeting? Print this page: the print layout carries the ten questions and nothing else.

Read it yourself

General information, not legal advice. Whether and how the Cyber Resilience Act applies to your products is for you and your counsel to decide.

Start free trial

Book a call