What to tell your users after you notify the CSIRT
Article 14(8) asks you to inform affected users after an actively exploited flaw. What it requires, what it leaves to you, what to draft now.
Today The Hacker News reported a Cisco Secure Email Gateway flaw exploited in the wild, with root command execution at the end of it: https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html
A vendor that size has an advisory page, a version matrix, and people whose job is to write the notice. Most of us reading this do not. And the part that gets skipped in a small team's procedure is never the reporting. It is what comes after.
The path does not stop at ENISA
Article 14 sets the reporting chain. Early warning within 24 hours of becoming aware, full notification within 72 hours, to the CSIRT designated as coordinator in your member state and to ENISA. The final report comes 14 days after a corrective or mitigating measure is made available.
Then Article 14(8) adds a separate duty, aimed at a different audience. After you become aware of an actively exploited vulnerability or a severe incident, you inform the affected users, and where appropriate all users, without undue delay.
Two audiences, two messages, one clock that started when you learned about it.
What the paragraph asks for
Three things.
You tell them about the vulnerability or the incident. Where necessary, you tell them about the mitigating and corrective measures they can apply. Where possible, you do it in a structured, machine-readable format.
That last one matters more than it looks. A sentence in a changelog is readable by a human who happens to be looking. A structured advisory can be consumed by whatever the user runs to watch their own dependencies.
What it leaves open
The regulation gives no template for this message. None. No fixed channel, no word count, no required fields.
It gives you a standard instead: without undue delay. You decide what carries it. Email to licence holders, an advisory page, a release note, an in-app banner, a post on the account where your users already follow you.
You also decide who counts as affected. Users on the vulnerable versions are the obvious set. The harder question is the installs you cannot see.
A two-person example
Take a team of two shipping a self-hosted invoicing app as a Docker image. Around 300 installs. Licence keys give them an email address for maybe half.
On a Tuesday morning a customer's security team sends evidence that a flaw in the upload endpoint was used on their server. That evidence is what Article 3(42) describes: a malicious actor exploited the vulnerability in a system without the owner's authorisation. The 24-hour clock starts at that email, not when someone writes back to them.
They file the early warning, and then the second half of the work starts.
Affected users are the installs running the vulnerable tags. They can mail the ones they have addresses for. The rest have no inbox they can reach, which is where "where appropriate, all users" does the work: a public advisory on the site, pinned where the image is published, so an operator who checks finds it.
The message they send says the version range, what an attacker can do with it, what to do this morning, and when a fix lands. Four things. If the fix is not ready, the mitigation is the message.
Write the message before you need it
The worst moment to decide your tone and your fields is the morning you need them. Draft the skeleton now and leave the blanks empty.
Product and affected versions. One sentence on what happened. What an operator should do today. Whether a fix exists and when. Where to check for updates. An address to write back to.
That last line ties into Annex I, Part II, points 5 and 6: a coordinated vulnerability disclosure policy and a contact address. The address is how you hear about the flaw in the first place. The message is how your users hear about it from you.
What applies now, what waits
Article 14 has applied since 11 September 2026. The duty to inform users lives inside it, so it applies now too.
The rest of the regulation arrives on 11 December 2027: the essential requirements of Annex I, the SBOM, the technical documentation, the EU declaration of conformity, and the penalties of Article 64.
If you are unsure whether any of this points at you, the free scope test walks eight questions with the article references and gives you a written, indicative assessment. It is not a verdict: https://crakit.eu/scope/
Not legal advice.
This is not legal advice.