Write your 24-hour reporting procedure on one page
Article 14 applies tomorrow. The five lines that say who takes the call, who decides, and where the notification goes.
The reporting duties start tomorrow. If you sell software and you have no lawyer, the useful question is narrow. What do you write down before tomorrow?
The whole thing fits on one page, in five lines. Here is what goes on them.
What starts tomorrow
Article 14 of the Cyber Resilience Act applies from 11 September 2026. A manufacturer who learns that a vulnerability in their product is actively exploited sends an early warning within 24 hours and a full notification within 72 hours. The same deadlines cover a severe incident that has an impact on the security of the product (Article 14(3)).
The count starts when you become aware. Not when an authority writes to you.
The ENISA single reporting platform becomes operational the same day (Article 16). The rest of the regulation waits for 11 December 2027. Technical documentation, SBOM, EU declaration of conformity, and the penalties in Article 64 all land on that date.
Line one, who takes the call
Name one person and one channel. The channel is a mailbox you actually read, published where a stranger can find it. A security.txt file at the RFC 9116 location does that job.
Add a fallback name.
Line two, who decides
Someone has to say yes or no to a single question. Is this actively exploited?
Article 3(42) sets the bar. Reliable evidence that a malicious actor has exploited the vulnerability in a system without the owner's authorisation. A CVE in a dependency does not clear that bar on its own. A customer log showing an attacker using the flaw on their production server does.
Write the name of the person who makes that call. Write the name of the person who makes it when the first one is on a plane. Two names, one line.
Line three, where it goes
Two recipients. The CSIRT designated as coordinator in your member state, and ENISA.
Put the actual contact details on the page today, while you have time to look them up. Create the platform account before you need it. Article 15 covers voluntary notification if you want to report something that falls outside the duty.
Line four, what users get
Article 14(8) asks you to inform the affected users without undue delay, and where relevant all users, about the vulnerability or the incident. Where necessary, tell them the mitigating and corrective measures they can apply. A structured, machine readable format where possible.
The regulation sets no template for that message. So write yours now. A short mail, a changelog entry, and a decision on who presses send.
Line five, the final report
Two different deadlines, and people mix them up.
For a vulnerability, the final report is due 14 days after a corrective or mitigating measure is made available. For a severe incident, one month after the notification. Put both on the page with an owner next to each.
A made-up case
I invented this publisher to show the page in use.
Two people sell a self-hosted backup agent for Postgres. Around 120 paying customers. On a Sunday at 22:40 a customer writes in. Their logs show someone using a bug in the agent's restore endpoint to run commands on their server.
That report clears the Article 3(42) bar. Reliable evidence, a real system, no authorisation.
They had written this down. Marie takes the call, on the number listed in security.txt. Either founder can decide alone at night. Submission goes through the ENISA platform account, and the login lives in the shared vault. The customer mail template sits in the repo at docs/notify.md.
The early warning went out at 23:20. Everything on that path had been settled weeks earlier, except the judgement on the evidence itself.
Without it, the same Sunday evening starts with two people searching for the address of their national CSIRT.
What the page does not do
It does not tell you whether Article 14 applies to you at all. That depends on whether you are a manufacturer under Article 3(13) and whether your product falls inside Article 2. A browser only SaaS sits outside the regulation under recital 12. An open source project with no commercial activity behind it sits outside under recital 18. A paid plugin sold under your own name sits inside.
If you are unsure which case you are in, run the free scope test. Eight questions, with the article references next to each answer: https://crakit.eu/scope/
One more thing worth knowing if you are small. Article 64(10)(a) says micro and small enterprises face no fine for missing the 24-hour early warning deadline on its own. Open source stewards face no fine at all, under point (b). Penalties start on 11 December 2027 in any case.
Writing it still matters. A procedure that exists on 11 September is a procedure you can improve later. One that does not exist gets written at 22:40 on a Sunday.
Not legal advice.
This is not legal advice.