Implementing CRA reporting: building a PSIRT and an Article 14 reporting process
Art. 14 · applies since 11 Sep 2026

Reporting process and PSIRT

Implementing CRA reporting: building a PSIRT and an Article 14 reporting process

Since 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe security incidents, including for products already on the market. We build a process with you that is designed around these deadlines: intake, assessment, decision, notification and informing users.

What Article 14 requires

Notifications go through the single reporting platform simultaneously to the CSIRT designated as coordinator and to ENISA. The clock starts when you become aware, including at night and at weekends. Anyone who reports therefore needs criteria agreed in advance, reachable roles with deputies and prepared templates.

The obligation applies to products placed on the market before 11 December 2027 as well as to new ones (Art. 69(3)). In addition, affected users must be informed about the vulnerability or incident and possible mitigations (Art. 14(8)).

The deadlines at a glance

Both triggers share the first deadlines; the final report differs.

TriggerEarly warningNotificationFinal report
Actively exploited vulnerabilitywithout undue delay, within 24 hours of becoming awarewithout undue delay, within 72 hours of becoming awareno later than 14 days after a corrective or mitigating measure is available
Severe security incidentwithout undue delay, within 24 hours of becoming awarewithout undue delay, within 72 hours of becoming awarewithin one month of the notification

Simplified summary of Article 14(2) and (4) of Regulation (EU) 2024/2847: the notification and final report are not required where the information has already been provided. The wording of the Regulation is authoritative: https://eur-lex.europa.eu/eli/reg/2024/2847/oj

Service modules

What we build with you.

Intake and availability

How reports of vulnerabilities and incidents come in, including outside business hours, and who sees them first.

Decision aid

Criteria for "actively exploited" (Art. 3(42)) and "severe incident" (Art. 14(5)), so the question is not first debated in an emergency.

Roles and deputies

Who assesses, decides and reports, with deputies and coordination with customers, suppliers and group entities, so that nobody reports twice or not at all.

Runbook and templates

Steps for early warning, notification and final report, templates with the required information, informing users.

PSIRT operation

Placing the product security incident response team in the organisation, connected to vulnerability handling and the SBOM chain.

SBOM and vulnerability management

CVD policy and security.txt

Public coordinated vulnerability disclosure policy and contact address under Annex I Part II(5) and (6).

CVD policy generator

What you end up with

A reporting process designed around the deadlines.

  1. 01

    Role and deputy matrix

    Named people per task, reachable.

  2. 02

    Runbook

    For all Article 14 deadlines, with a decision aid.

  3. 03

    Templates

    For early warning, notification, final report and user information.

How we work

Because the obligation already applies, we start with what is needed first in an emergency.

  1. 1

    Free initial call

    Products, existing processes, customers and group structures. You then receive a proposal with a clearly defined scope.

  2. 2

    Immediate measures

    Agree availability, roles and a first decision aid.

  3. 3

    Runbook

    Steps, templates and coordination with the parties involved.

  4. 4

    Review

    Walk through the runbook with the parties involved, close gaps.

  5. 5

    Embedding

    Connect to vulnerability handling, the SBOM chain and the technical documentation.

What we do not do

So that expectations are right:

  • You submit Article 14 notifications yourself; we prepare the process, roles and templates.
  • No legal services: you decide whether an event is reportable; legally open cases are flagged for review by your legal department or counsel.
  • No 24/7 on-call service; availability is ensured by your named roles.

The reporting obligation remains with your company. We help you meet it and document the evidence.

Frequently asked questions

Do we need a dedicated PSIRT?+

The CRA does not prescribe a particular organisational form. It requires you to handle vulnerabilities and meet the Article 14 deadlines. Whether a dedicated team, a role in the existing security team or a group function is responsible, we decide with you.

Does the reporting obligation apply to older products?+

Yes. Article 14 also applies to products placed on the market before 11 December 2027 (Art. 69(3)).

Where do notifications go?+

Through the single reporting platform under Article 16, simultaneously to the CSIRT designated as coordinator and to ENISA.

What does building the reporting process cost?+

It depends on the number of products, existing processes and the parties involved. After a free initial call you receive a proposal with a clearly defined scope.

Further reading

This content provides general technical and organizational information on the Cyber Resilience Act (Regulation (EU) 2024/2847) and does not constitute legal advice (no legal services within the meaning of the German RDG).

Last updated: 2026-10-08

Kontakt aufnehmen

Build your reporting process

The obligation already applies. Tell us about your products and processes. The initial call is free and without obligation; we usually reply within one to two working days.