CRA Kit
Blog · · 2 min read · CRA · Cyber Resilience Act

A gateway flaw can start your 24-hour clock

A gateway you didn't build can trigger your Article 14 clock once it's actively exploited and your product sits behind it.

What counts as active exploitation

A catalog like CISA's Known Exploited Vulnerabilities list only lists vulnerabilities with confirmed exploitation, not every disclosed CVE. Article 3, point 42 of the Cyber Resilience Act defines "actively exploited" the same way: reliable evidence that someone used a flaw without the owner's authorization.

A gateway flaw that lands on that kind of list sits in front of a lot of products their own builders never touched. That's exactly the kind of evidence article 14 cares about.

Why someone else's gateway becomes your incident

Article 14, paragraph 5 covers a serious incident: one that affects or may affect your product's ability to protect the availability, authenticity, integrity, or confidentiality of sensitive or important data or functions, or that has led or may lead to malicious code being introduced or executed in your product or your users' systems. A vulnerable gateway sitting in front of your product can reach both prongs. Once you know it's actively exploited and your product sits behind it, that knowledge is what starts your clock, not the exploit itself.

A concrete case

Say you sell an invoicing app for desktop, under your own name, with a paid license. That makes you a manufacturer under article 3, points 13 and 22: you develop the product and place it on the market as part of a commercial activity. Your backend sits behind a gateway that gets breached through a flaw like that, and an attacker reaches your customers' invoices. You now know about a serious incident. Article 14 gives you 24 hours for an early warning to the CSIRT designated as coordinator in your member state and to ENISA, and 72 hours for the full notification. The clock started the moment you knew, not when the gateway vendor patched, not when a customer called.

What's still ahead

No fine attaches to a missed 24-hour window today. Article 64's fines start from 11 December 2027, alongside the rest of the regulation: SBOM, technical documentation, the declaration of conformity. Today's duty is narrower and already live: know about the incident, then notify.

Whether you're a manufacturer under the CRA at all is the question that decides everything above. The scope test takes two minutes: https://crakit.eu/scope/

Not legal advice.

This is not legal advice.

LD
Louann Duclos

Built CRA Kit. Writes here about what the regulation asks of a small software company. All posts · RSS feed