Skip to content
11 days until the Art. 14 reporting obligation (11 September 2026).
Documentation Support Risk class
00Glossary

The words of the regulation, with the article alongside

Twenty-six entries that come up in every discussion with your lawyer, your client or the authority. The definitions follow the text of Reg. (EU) 2024/2847; the “what it entails” note says what changes in practice. Each entry has its own anchor you can link to.

These words come to life in the Art. 14 reporting obligations; if you are unsure whether they apply to you, take the two-minute applicability test.

26 entries of 26

A software or hardware product, and its remote data-processing solutions, placed on the Union market such that the logical or physical connection to a device or network is an intended function.

What it entails

If the product connects, it falls under the regulation: this applies to industrial firmware, apps, home devices and components sold separately.

Manufacturer Art. 3(13)

Anyone who develops or has a product with digital elements developed and markets it under their own name or trademark, whether for payment or free of charge.

What it entails

Anyone who puts their own brand on a product developed by third parties takes on the manufacturer's obligations, including reporting.

A vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without the owner's authorisation.

What it entails

It is the precondition for the 24-hour early warning. A vulnerability merely reported by a researcher does not trigger the obligation, but the assessment must be documented.

An incident that negatively affects, or is capable of negatively affecting, the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or that has led, or is capable of leading, to the introduction or execution of malicious code.

What it entails

It follows a chain parallel to that of vulnerabilities: 24 hours, 72 hours and a final report within one month of the incident notification.

Early warning Art. 14(2)(a)

First communication to the designated CSIRT and to ENISA, within 24 hours of becoming aware, indicating whether the vulnerability is exploited and in which Member States the product is available.

What it entails

It does not require a complete analysis: it requires timeliness. Delay is the easiest breach to challenge.

Communication within 72 hours of becoming aware, with general information on the product, the nature of the exploitation, severity and corrective measures available or taken.

What it entails

It is where you correct and supplement what was said in the early warning: this is why the content of the early warning is locked.

Final report Art. 14(2)(c) · 14(4)(c)

The closing report on the event and the measures taken: for vulnerabilities, within 14 days of the corrective measure becoming available; for severe incidents, within one month of the incident notification.

What it entails

Two different deadlines that are often confused. The regulatory engine calculates them based on the qualification of the event.

Moment of awareness Art. 14(1)

The moment the manufacturer becomes aware of the exploited vulnerability or the incident. All deadlines run from here.

What it entails

It must be fixed precisely and preserved: it is the first piece of data the authority checks to establish whether the deadline was met.

The single reporting platform established by ENISA, with national access points, through which the manufacturer files notifications.

What it entails

Filing is an act of the manufacturer using its own credentials: no vendor can notify on your behalf.

Coordinated vulnerability disclosure Annex I, Part II, points 5–6

A public policy describing how to receive and handle vulnerability reports, with a reachable point of contact.

What it entails

You need a public channel and a written policy: the reporting form embedded in the site satisfies this requirement.

Software bill of materials (SBOM) Annex I, Part II, point 1

A formal, machine-readable document listing the product's software components and their dependencies, at least at the top level.

What it entails

Without an SBOM you cannot know which products a third-party component vulnerability affects, nor whom to report it to upstream.

Upstream reporting Art. 13(6)

The obligation to report to the component's maintainer a vulnerability found in a component, including open source, integrated into the product.

What it entails

It is a distinct and often forgotten obligation: in the application it appears as a task when the product has third-party components.

Notice to users Art. 14(8)

Information to the product's users about the vulnerability or the incident and, where appropriate, about the corrective or mitigation measures they can adopt.

What it entails

To be circulated without undue delay. A copy must be kept: it is the proof that the market was informed.

Support period Art. 13(8)

A period, as a rule not less than five years, during which the manufacturer ensures the effective handling of vulnerabilities.

What it entails

It must be declared to the market and kept in the product register: it defines how long you remain obliged to provide updates.

Categories of products whose cybersecurity-critical function entails stricter conformity assessment procedures.

What it entails

The classification changes the conformity procedure, not the reporting obligations: those apply to everyone.

Critical product Annex IV

Products for which the Commission may require mandatory European cybersecurity certification.

What it entails

If you make security hardware or smart meters, check the list: mandatory certification changes the time and cost of conformity.

CE marking Art. 30

Marking that attests the product's conformity with the essential requirements of the regulation and with other applicable acts.

What it entails

Without a declaration of conformity and consistent technical documentation, the marking can be challenged.

The national authority that verifies product conformity, may request documentation, order corrective measures and withdrawal from the market.

What it entails

Requests for documentation come with short deadlines: the defensive dossier exists to respond without reconstructing anything.

The fines Member States impose for breaches of the regulation: up to 15 million euro or 2.5% of annual worldwide turnover for the essential requirements and the obligations of Art. 13 and 14; lower amounts for other breaches.

What it entails

The calculation takes into account cooperation and the measures taken: the documentation of due diligence affects the outcome.

Designated CSIRT Art. 14(1)

The national computer security incident response team that receives notifications together with ENISA. In Italy, CSIRT Italia at the ACN.

What it entails

The company contact point must be designated and validated before the emergency, not during it.

Corrective measure Art. 14(2)(c)

A security update or other measure that eliminates or mitigates the vulnerability.

What it entails

Its availability date starts the final-report deadline for exploited vulnerabilities.

Importer and distributor Art. 19 · 20

Those who place on the Union market a product from a third-country manufacturer, or make it available, with their own verification and information obligations.

What it entails

If they discover an exploited vulnerability they must inform the manufacturer and, in certain cases, the authorities: they too need to keep a record.

EU Login Art. 16

The European Commission's authentication system used to access the Union's digital services, including the national access points to the ENISA single reporting platform.

What it entails

Credentials must be created and verified in advance: on the day of the emergency there is no time to register and wait for confirmation.

EU Login · official website

security.txt Annex I, Part II, point 5

A standardised text file, published at /.well-known/security.txt, that states the point of contact for reporting vulnerabilities and the disclosure policy.

What it entails

It is the simplest way to make the channel required by coordinated disclosure reachable and verifiable.

ENISA Art. 16 · 17

The European Union Agency for Cybersecurity, which operates the single reporting platform and receives notifications together with the national CSIRTs.

What it entails

It is one of the two recipients of the early warning and notification: the filing goes to ENISA and to the designated CSIRT.

ENISA · official website

Due diligence Art. 13(5)

The manufacturer's obligation to exercise due diligence on third-party components integrated into the product, so that they do not compromise its cybersecurity.

What it entails

Documenting due diligence — selection, verification and updating of components — is part of the dossier the authority may request.

Definitions are not enough: you have to apply them under pressure

In the CRAnotify triage, every question cites the article that governs it, so the qualification remains defensible even months later.

See it in a demo