EU · Cyber Resilience Act Art. 14

Your 24h / 72h / 14d reporting, stamped before 11.09.2026.

From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents. Early warning in 24h, full notification in 72h, final report in 14 days. Vigil checks your readiness — in 60 seconds.

Art. 14: 11.09.2026 24h / 72h / 14d Fine: up to €15M / 2.5%
The rule

Three reporting windows that start in 29 days

The Cyber Resilience Act (Regulation (EU) 2024/2847) applies to every product with digital elements. Its Article 14 reporting duties go live on 11 September 2026.

SRP

Single Reporting Platform

Report once through the CRA Single Reporting Platform (ENISA) to your CSIRT.

ENISA
Readiness check

3 questions, your reporting gap stamped

Everything runs in your browser. No data leaves your device, no account needed.

Question 1 of 3

Do you manufacture products with digital elements placed on the EU market?

Question 2 of 3

Do you monitor your products for actively exploited vulnerabilities and severe incidents?

Question 3 of 3

Do you have a process to notify ENISA/CSIRT within 24h / 72h / 14d once aware?

How it works

From question to stamped readiness

1

Answer 3 questions

Manufacturer scope, vulnerability monitoring, notification process. Vigil maps your case against Article 14 of Regulation (EU) 2024/2847.

2

Get your alert stamp

The stamp shows your reporting gap — monitoring, notification runbook or both — with a live countdown to 11.09.2026.

3

Work the checklist

SBOM, CVE tracking, CSIRT contact, SRP onboarding — step by step against the 24h/72h/14d windows.

Pricing

Check for free. Print your gap for 15 $.

Free

0 $
  • Your Art. 14 reporting gap
  • Fine exposure (€15M / 2.5%)
  • Checklist: SBOM, CVE, SRP
  • Links to official sources
  • Printable readiness stamp (PDF)
  • Notification runbook template
Check for free
Recommended

Pro

15 $ one-time
  • Everything in Free
  • Printable readiness stamp (PDF)
  • 24h/72h/14d notification runbook
  • Art. 14 readiness checklist
  • Permanent unlock

One-time payment in USDT/USDC. Permanent unlock. Price in USD; taxes per your country at checkout.

FAQ

What manufacturers are asking right now

When does Art. 14 reporting start?
On 11 September 2026, the Cyber Resilience Act's vulnerability and incident reporting obligations (Art. 14) become applicable. Manufacturers must report actively exploited vulnerabilities and severe incidents affecting their products with digital elements. [1][2]
What are the reporting deadlines?
Three windows once you become aware: an early warning within 24 hours, a full notification within 72 hours, and a final report within 14 days of a corrective measure (within a month for severe incidents). [1][4]
Where do I report?
Once, through the CRA Single Reporting Platform (SRP), operated by ENISA and operational by 11 September 2026. The notification goes to the CSIRT of your main establishment and is shared with the CSIRTs where your product is available. [1]
Who is in scope?
Manufacturers of products with digital elements placed on the EU market — including software, firmware, connected hardware and apps. Full conformity obligations (CE marking, essential requirements) follow on 11 December 2027. [3][5]
What are the fines?
Top-tier infringements — including failures of the reporting obligations — can reach €15,000,000 or 2.5% of worldwide annual turnover, whichever is higher (Art. 64). [3]
Does Vigil connect to my systems?
No. You answer 3 questions and everything is computed in your browser. No data is sent to any server and nothing is connected to your code, infrastructure or accounts.
Sources

Where the data comes from

Every claim links to its source. Verified on 13 August 2026.

1
European Commission — Cyber Resilience Act: reporting obligationsPrimary source (updated 31 July 2026): from 11 September 2026 manufacturers report actively exploited vulnerabilities and severe incidents — 24h early warning, 72h notification, 14-day final report — once via the SRP to the CSIRT.
2
Hogan Lovells — Preparing for CRA vulnerability and incident reportingConfirms the reporting obligations apply from 11 September 2026 to all products with digital elements within scope.
3
CRA Evidence — Manufacturer obligationsManufacturer duties under the CRA and penalty exposure: top-tier infringements up to €15M or 2.5% of worldwide turnover.
4
Zealience — CRA Article 14 reportingDetailed walk-through of the 24h / 72h / 14d notification windows and what the SRP requires.
5
ContinueOps — CRA compliance timeline 2026–2027Key dates: reporting obligations 11 September 2026; full conformity obligations 11 December 2027.

Close your reporting gap before 11 September 2026 — the 24h clock starts the moment you're aware.

Check your readiness and get your alert stamp in one minute. Free, no account — nothing leaves your device.

Check my readiness