When do the 24 hours start? The awareness anchor
The Art. 14 deadlines do not run from when a manager opens the email, nor from Monday morning, nor from the alignment meeting. They run from the moment the company becomes aware of the fact. That instant is the first data point an authority checks — and it is an organisational problem before it is a technical one.
The awareness moment, and why an authority looks at it first
Art. 14(1) anchors every deadline to a single instant: the moment the manufacturer becomes aware of an actively exploited vulnerability or of a severe incident affecting the security of the product. From that instant the 24 hours of the early warning begin to run, and the whole subsequent chain hangs off it. This is what we call the moment of awareness.
It is the first thing an authority checks precisely because it is a single date and time, not an interpretation. To decide whether a deadline was met, the inspector does not need to enter the merits of the vulnerability: it is enough to compare two timestamps — the instant of awareness and the instant of filing. Everything else follows from that subtraction.
A technical clock that is won or lost on the organisation
Once the anchor is understood, the problem shifts sideways: from the technical domain to the organisational one. The 24 hours are not spent understanding the bug — they are spent noticing, in time, that someone has written to you. To keep that window from closing on its own you need three things: a single, staffed intake channel; a written rule stating who assesses the report and against which criteria; and an on-call chain with hourly thresholds and named substitutes.
The companies we have seen in trouble did not lack competence: their engineers could have analysed the vulnerability in an hour. They lacked availability. The report arrived on a channel no one was watching, or it reached a person who was off for the weekend with no substitute behind them. The deadline was missed not on the merits but on the roster.
Fixing and documenting the instant, so it holds up months later
Knowing the deadline runs from awareness is worth little if you cannot prove when awareness occurred. The instant has to be fixed at the moment it happens, not reconstructed later from memory. In practice this means an intake that timestamps every incoming report automatically, and a tamper-evident log entry — one that records the arrival, the time, the source and who took it in hand, and that no one can silently edit afterwards.
The point of the tamper-evidence is defensibility. Months after the fact, in front of an inspector, you do not want to be arguing about when you knew: you want a record produced at the time, whose date cannot have been moved backward or forward to suit the story. A timestamped intake and a write-once log turn a contestable memory into a fact.
23:40 on a Saturday: walking the clock
A report reaches the public address at 23:40 on a Saturday: a researcher writes that a vulnerability in your product is being exploited in the wild. That timestamp — 23:40 Saturday — is the instant you will have to defend. The 24 hours do not wait for the office to reopen: the early warning is due by 23:40 on Sunday.
Walk the clock. If the on-call chain works, at 23:45 the report is timestamped and logged; by 00:30 the person on duty has confirmed there is reliable evidence of exploitation; by mid-morning Sunday the early warning is filed, with fourteen hours of margin. If instead the message sits unread until Monday at 09:00, awareness is still fixed at 23:40 on Saturday — the law does not move the anchor — and thirty-three hours have gone by, nine of them past the deadline, before anyone has read a line.
The anchor and the register are the same discipline
The instant of awareness is the first entry in a chain of evidence that runs across the whole life of a report: awareness, qualification, early warning, 72-hour update, final report. Each of these has its own deadline, each counted from the anchor or from the step before it, and each is worth defending only if it was recorded when it happened. The timestamped log is not bureaucracy — it is what makes every later deadline provable.
The exact deadline chains — which one applies to an exploited vulnerability and which to a severe incident, and how the final reports differ — are set out in our pillar on Art. 14. Read the anchor and the chains together: the first tells you when the count starts, the second what it counts down to.
This article describes our reading of the regulatory text and does not constitute legal advice.
Risk class