Article 14 Reportability Triage
Article 14 of Regulation (EU) 2024/2847 (Cyber Resilience Act) requires manufacturers to report actively exploited vulnerabilities and severe security incidents.
The CRA Article 14 Reportability Checker at https://cvdportal.com/tools/reportability-check provides an anonymous, client-side triage tool. It evaluates whether an event requires statutory notification to ENISA and the national CSIRT coordinator.
How the triage tool evaluates events
The tool evaluates three primary factors:
- Event type. The user selects a vulnerability, a security incident, or both.
- Active exploitation. For vulnerabilities, the tool checks for active exploitation in the wild. Under Article 14(1) and Commission guidance C(2026) 5252, theoretical exploitability and proof-of-concept demonstrations do not trigger statutory reporting. Real-world attack evidence is required.
- Incident severity. For security incidents, the tool checks severity under Article 14(5). An incident is severe if it impacts data confidentiality, integrity, availability, or authenticity, or if it executes unauthorized malicious code.
Statutory deadlines
When an event triggers Article 14, the tool calculates live deadlines from the recorded awareness timestamp:
- 24-hour early warning. The manufacturer must submit initial notification within 24 hours of becoming aware.
- 72-hour notification. The manufacturer must submit detailed technical information within 72 hours of becoming aware.
- Final report. For vulnerabilities, the final report is due within 14 days after a corrective measure is available. For incidents, the final report is due within one calendar month after the 72-hour notification. For both, the earlier deadline applies.
The tool executes entirely in the web browser. It does not store data in a database and does not transmit notifications to authorities.