CRA incident reporting: questions people actually ask
Straight answers on the Article 14 clocks. Where something is a legal determination rather than a fact, we say so instead of guessing.
Last reviewed 2026-09-04 · IncidentReady, Harmony Future Holdings Limited, Dublin
When exactly does the 24-hour clock start?
At the moment you became aware — not when you finished investigating, not when you were certain, and not when management was briefed. If a customer emailed you on Tuesday and your engineer confirmed it on Thursday, expect the regulator’s question to be about Tuesday.
Does a published CVE against our product start the clock?
Not on its own. The trigger is reliable evidence of actual exploitation by a malicious actor without the user’s consent. A CVE with no evidence of exploitation does not meet that definition. A CVE plus credible reports of it being used in the wild does. This is a judgement call, and it is the one worth writing down at the time you make it.
Do weekends and public holidays extend the deadline?
No. The 24-hour and 72-hour clocks run in absolute hours. An event you become aware of at 18:40 on Friday has its early warning due by 18:40 on Saturday. This is why an out-of-hours call path is not optional.
We are not sure whether it counts as actively exploited. What do we do?
Treat the clock as running and start the log. A log you did not need costs an hour; a clock you started late cannot be un-started. The early warning asks for very little — you can file it while the analysis is still open, and “unknown” is an acceptable answer to the malicious-acts question at 24 hours.
What if an event is both an exploited vulnerability and a severe incident?
Both sets of obligations run. They do not merge. The two tracks have different final-report anchors: the vulnerability final report is due 14 days after a corrective or mitigating measure becomes available; the incident final report is due within one month of the 72-hour notification.
Who do we actually file with?
The ENISA Single Reporting Platform. One submission routes simultaneously to ENISA and to the CSIRT coordinator of the member state where you have your main establishment (Art. 14, Art. 16).
Does this obligation pass to our distributor or reseller?
No. Article 14 reporting sits with the manufacturer of the product with digital elements. It does not transfer down the distribution chain, and a contract with your reseller does not move it.
Our product is not sold in the EU. Are we clear?
Clear of Article 14, yes. Not clear generally — GDPR, NIS2 and your own customer contracts have separate triggers and separate clocks, and neither this site nor our pack covers them.
Do we have to tell our users, or just the regulator?
Both, and in parallel. Article 14(8) requires you to inform impacted users — and where appropriate all users — without undue delay, including about mitigations they can apply themselves. It is a decision that runs alongside the regulator clocks, not a step afterwards.
What are the penalties for filing late?
The regulation sets a ceiling of €15,000,000 or 2.5% of worldwide annual turnover, whichever is higher, for non-compliance with essential requirements and core obligations (Art. 64). Which band applies to a late early warning specifically is a legal determination. We do not assert it, and you should not rely on anyone who does without a lawyer’s name on it.
When does all this start applying?
The Article 14 reporting obligations apply from 11 September 2026, via the ENISA Single Reporting Platform.
Is the free tool on this site the same as the paid pack?
The classifier is the same logic — the free tool is a faithful port of the function the paid pack uses, so the verdict and the dates match. What the free tool cannot do is name your incident lead, pre-draft the notifications with your product versions in them, or give you the evidence register and the gap list. That is what the €490 pack is.
Is any of this legal advice?
No. This site is internal-readiness documentation. It is not legal advice, it is not a conformity assessment, and nothing here submits anything to ENISA or any CSIRT. Reporting obligations rest with the manufacturer. Verify against the regulation and current ENISA guidance before relying on any of it during an incident.
Your runbook, specific to your company
The free tools on this site tell you what the law asks. The pack tells you who in your company does it, with the notifications already drafted and your product versions already in them.
Get the pack — €490