A documented "no" is worth as much as a "yes": how a manufacturer defends itself
Deciding not to report is a legitimate outcome. But it protects you only if it was reasoned and written down at the time, not reconstructed afterwards. Under a market-surveillance inspection, an undocumented correct decision looks exactly like an omission.
The asymmetry: the authority verifies the process, not just the outcome
When an inspector looks at a case, they are not asking "did you report or not?". They are asking whether you were in a position to decide, and whether you decided in a traceable way. This is the point almost everyone misses: a defensible file with a written "no" beats an undocumented "yes" every time, because the first shows a working process and the second shows only luck.
A manufacturer who reported everything, out of prudence, but cannot explain why, is in a weaker position than one who reported nothing because — case by case — none of the events met the threshold, and can prove it. The obligation is not to report: it is to qualify each event correctly and to act on the qualification. The reporting obligations of Art. 14 presuppose an assessment; the assessment is what the authority inspects.
What a good record contains
A record that holds up is not a long document. It is a short one that answers six questions without hedging. The event: what arrived and through which channel. The moment of awareness: the timestamp from which any deadline runs, recorded when it happened. The qualification: exploited or not, incident or not — with the article applied written next to it, because that article is what fixes the deadlines.
Then the reasoning: two or three sentences on why the event was qualified that way. The evidence: the log, the email, the scanner output, the analyst's note — whatever the reasoning relies on. And finally the deadlines computed: even when the conclusion is "no obligation", writing the deadlines you would have faced proves you knew the clock existed. Miss the qualification step and you cannot compute anything, which is the most common defect in the internal processes we are shown.
The authority can ask on short notice
The market surveillance authority can request the documentation demonstrating conformity, and it can do so with little warning and no obligation to explain why it is asking. A defensive dossier exists precisely so that you answer with what already exists, rather than reconstructing months of decisions under pressure — a reconstruction that, however honest, always reads as after-the-fact.
The difference between the two situations is not the quality of your engineering. It is whether the decision was captured at the moment it was made. A record written on the day is evidence; the same content typed the week of the inspection is a story, and inspectors know the difference.
Due diligence and cooperation reduce exposure
The sanctions are not theoretical. A breach of the Art. 13 and Art. 14 obligations can reach fifteen million euro or 2.5% of worldwide annual turnover, whichever is higher. But the regulation asks authorities to weigh the nature and gravity of the infringement, whether it was negligent or intentional, and the degree of cooperation shown. A documented process is the concrete form that "due diligence" takes.
Two manufacturers with the same missed report are not treated the same way. The one who can show that it assessed the event, reached a defensible conclusion in good faith, and cooperated once the error emerged, argues from a position the other does not have. The file does not only prevent the omission — it shapes the response when something goes wrong anyway.
A concrete example: the dependency judged "not exploited"
A scanner flags a known vulnerability in a third-party library bundled in your product. The engineer looks at it and concludes it is not exploitable in your configuration: the vulnerable code path is never reached. The conclusion is probably right. Recorded nowhere, it is worth nothing in six months.
Here is the one paragraph that would hold up. "CVE-XXXX-NNNN reported by the SBOM scan on 5 August 2026, 09:12, in library X v2.3, component of product Y. Assessed same day: no reliable evidence of exploitation in the wild; the affected function is not invoked in our build (call graph attached). Qualified as non-exploited vulnerability under Art. 3(42): early warning obligation of Art. 14 not triggered. Patch scheduled for the next maintenance release. Reviewer: [name]." That is enough. It names the event, the timestamped awareness, the qualification with its article, the reasoning, the evidence, and the fact that the deadline clock was consciously checked and found not to have started.
Multiply that paragraph by the handful of events that cross your channel each month and you have a defensive dossier that costs minutes to keep and answers an inspection without a single reconstruction. The "no" is documented, and a documented "no" is worth as much as a "yes".
This article describes our reading of the regulatory text and does not constitute legal advice.
Risk class