
Reporting process and PSIRT
Implementing CRA reporting: building a PSIRT and an Article 14 reporting process
Since 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe security incidents, including for products already on the market. We build a process with you that is designed around these deadlines: intake, assessment, decision, notification and informing users.
What Article 14 requires
Notifications go through the single reporting platform simultaneously to the CSIRT designated as coordinator and to ENISA. The clock starts when you become aware, including at night and at weekends. Anyone who reports therefore needs criteria agreed in advance, reachable roles with deputies and prepared templates.
The obligation applies to products placed on the market before 11 December 2027 as well as to new ones (Art. 69(3)). In addition, affected users must be informed about the vulnerability or incident and possible mitigations (Art. 14(8)).
The deadlines at a glance
Both triggers share the first deadlines; the final report differs.
| Trigger | Early warning | Notification | Final report |
|---|---|---|---|
| Actively exploited vulnerability | without undue delay, within 24 hours of becoming aware | without undue delay, within 72 hours of becoming aware | no later than 14 days after a corrective or mitigating measure is available |
| Severe security incident | without undue delay, within 24 hours of becoming aware | without undue delay, within 72 hours of becoming aware | within one month of the notification |
Simplified summary of Article 14(2) and (4) of Regulation (EU) 2024/2847: the notification and final report are not required where the information has already been provided. The wording of the Regulation is authoritative: https://eur-lex.europa.eu/eli/reg/2024/2847/oj
Service modules
What we build with you.
Intake and availability
How reports of vulnerabilities and incidents come in, including outside business hours, and who sees them first.
Decision aid
Criteria for "actively exploited" (Art. 3(42)) and "severe incident" (Art. 14(5)), so the question is not first debated in an emergency.
Roles and deputies
Who assesses, decides and reports, with deputies and coordination with customers, suppliers and group entities, so that nobody reports twice or not at all.
Runbook and templates
Steps for early warning, notification and final report, templates with the required information, informing users.
PSIRT operation
Placing the product security incident response team in the organisation, connected to vulnerability handling and the SBOM chain.
SBOM and vulnerability managementCVD policy and security.txt
Public coordinated vulnerability disclosure policy and contact address under Annex I Part II(5) and (6).
CVD policy generatorWhat you end up with
A reporting process designed around the deadlines.
01
Role and deputy matrix
Named people per task, reachable.
02
Runbook
For all Article 14 deadlines, with a decision aid.
03
Templates
For early warning, notification, final report and user information.
How we work
Because the obligation already applies, we start with what is needed first in an emergency.
1
Free initial call
Products, existing processes, customers and group structures. You then receive a proposal with a clearly defined scope.
2
Immediate measures
Agree availability, roles and a first decision aid.
3
Runbook
Steps, templates and coordination with the parties involved.
4
Review
Walk through the runbook with the parties involved, close gaps.
5
Embedding
Connect to vulnerability handling, the SBOM chain and the technical documentation.
What we do not do
So that expectations are right:
- You submit Article 14 notifications yourself; we prepare the process, roles and templates.
- No legal services: you decide whether an event is reportable; legally open cases are flagged for review by your legal department or counsel.
- No 24/7 on-call service; availability is ensured by your named roles.
The reporting obligation remains with your company. We help you meet it and document the evidence.
Frequently asked questions
Do we need a dedicated PSIRT?+
The CRA does not prescribe a particular organisational form. It requires you to handle vulnerabilities and meet the Article 14 deadlines. Whether a dedicated team, a role in the existing security team or a group function is responsible, we decide with you.
Does the reporting obligation apply to older products?+
Yes. Article 14 also applies to products placed on the market before 11 December 2027 (Art. 69(3)).
Where do notifications go?+
Through the single reporting platform under Article 16, simultaneously to the CSIRT designated as coordinator and to ENISA.
What does building the reporting process cost?+
It depends on the number of products, existing processes and the parties involved. After a free initial call you receive a proposal with a clearly defined scope.
Further reading
- CRA reporting: 24 hours, 72 hours, final report
- Vulnerability handling and CVD
- Fines and penalties
- CRA checklist, step 7
- CRA consulting: all services
This content provides general technical and organizational information on the Cyber Resilience Act (Regulation (EU) 2024/2847) and does not constitute legal advice (no legal services within the meaning of the German RDG).
Last updated: 2026-10-08
Kontakt aufnehmen
Build your reporting process
The obligation already applies. Tell us about your products and processes. The initial call is free and without obligation; we usually reply within one to two working days.