The words of the regulation, with the article alongside
Twenty-six entries that come up in every discussion with your lawyer, your client or the authority. The definitions follow the text of Reg. (EU) 2024/2847; the “what it entails” note says what changes in practice. Each entry has its own anchor you can link to.
These words come to life in the Art. 14 reporting obligations; if you are unsure whether they apply to you, take the two-minute applicability test.
A software or hardware product, and its remote data-processing solutions, placed on the Union market such that the logical or physical connection to a device or network is an intended function.
If the product connects, it falls under the regulation: this applies to industrial firmware, apps, home devices and components sold separately.
Anyone who develops or has a product with digital elements developed and markets it under their own name or trademark, whether for payment or free of charge.
Anyone who puts their own brand on a product developed by third parties takes on the manufacturer's obligations, including reporting.
A vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without the owner's authorisation.
It is the precondition for the 24-hour early warning. A vulnerability merely reported by a researcher does not trigger the obligation, but the assessment must be documented.
An incident that negatively affects, or is capable of negatively affecting, the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or that has led, or is capable of leading, to the introduction or execution of malicious code.
It follows a chain parallel to that of vulnerabilities: 24 hours, 72 hours and a final report within one month of the incident notification.
First communication to the designated CSIRT and to ENISA, within 24 hours of becoming aware, indicating whether the vulnerability is exploited and in which Member States the product is available.
It does not require a complete analysis: it requires timeliness. Delay is the easiest breach to challenge.
Communication within 72 hours of becoming aware, with general information on the product, the nature of the exploitation, severity and corrective measures available or taken.
It is where you correct and supplement what was said in the early warning: this is why the content of the early warning is locked.
The closing report on the event and the measures taken: for vulnerabilities, within 14 days of the corrective measure becoming available; for severe incidents, within one month of the incident notification.
Two different deadlines that are often confused. The regulatory engine calculates them based on the qualification of the event.
The moment the manufacturer becomes aware of the exploited vulnerability or the incident. All deadlines run from here.
It must be fixed precisely and preserved: it is the first piece of data the authority checks to establish whether the deadline was met.
The single reporting platform established by ENISA, with national access points, through which the manufacturer files notifications.
Filing is an act of the manufacturer using its own credentials: no vendor can notify on your behalf.
A public policy describing how to receive and handle vulnerability reports, with a reachable point of contact.
You need a public channel and a written policy: the reporting form embedded in the site satisfies this requirement.
A formal, machine-readable document listing the product's software components and their dependencies, at least at the top level.
Without an SBOM you cannot know which products a third-party component vulnerability affects, nor whom to report it to upstream.
The obligation to report to the component's maintainer a vulnerability found in a component, including open source, integrated into the product.
It is a distinct and often forgotten obligation: in the application it appears as a task when the product has third-party components.
Information to the product's users about the vulnerability or the incident and, where appropriate, about the corrective or mitigation measures they can adopt.
To be circulated without undue delay. A copy must be kept: it is the proof that the market was informed.
A period, as a rule not less than five years, during which the manufacturer ensures the effective handling of vulnerabilities.
It must be declared to the market and kept in the product register: it defines how long you remain obliged to provide updates.
Categories of products whose cybersecurity-critical function entails stricter conformity assessment procedures.
The classification changes the conformity procedure, not the reporting obligations: those apply to everyone.
Products for which the Commission may require mandatory European cybersecurity certification.
If you make security hardware or smart meters, check the list: mandatory certification changes the time and cost of conformity.
Marking that attests the product's conformity with the essential requirements of the regulation and with other applicable acts.
Without a declaration of conformity and consistent technical documentation, the marking can be challenged.
The national authority that verifies product conformity, may request documentation, order corrective measures and withdrawal from the market.
Requests for documentation come with short deadlines: the defensive dossier exists to respond without reconstructing anything.
The fines Member States impose for breaches of the regulation: up to 15 million euro or 2.5% of annual worldwide turnover for the essential requirements and the obligations of Art. 13 and 14; lower amounts for other breaches.
The calculation takes into account cooperation and the measures taken: the documentation of due diligence affects the outcome.
The national computer security incident response team that receives notifications together with ENISA. In Italy, CSIRT Italia at the ACN.
The company contact point must be designated and validated before the emergency, not during it.
A security update or other measure that eliminates or mitigates the vulnerability.
Its availability date starts the final-report deadline for exploited vulnerabilities.
Those who place on the Union market a product from a third-country manufacturer, or make it available, with their own verification and information obligations.
If they discover an exploited vulnerability they must inform the manufacturer and, in certain cases, the authorities: they too need to keep a record.
The European Commission's authentication system used to access the Union's digital services, including the national access points to the ENISA single reporting platform.
Credentials must be created and verified in advance: on the day of the emergency there is no time to register and wait for confirmation.
A standardised text file, published at /.well-known/security.txt, that states the point of contact for reporting vulnerabilities and the disclosure policy.
It is the simplest way to make the channel required by coordinated disclosure reachable and verifiable.
The European Union Agency for Cybersecurity, which operates the single reporting platform and receives notifications together with the national CSIRTs.
It is one of the two recipients of the early warning and notification: the filing goes to ENISA and to the designated CSIRT.
The manufacturer's obligation to exercise due diligence on third-party components integrated into the product, so that they do not compromise its cybersecurity.
Documenting due diligence — selection, verification and updating of components — is part of the dossier the authority may request.
Definitions are not enough: you have to apply them under pressure
In the CRAnotify triage, every question cites the article that governs it, so the qualification remains defensible even months later.