OSPulse

Article 11 or Article 14? You report under Article 14.

Article 11 was the reporting article in the CRA’s 2022 proposal. In the Regulation that actually applies, (EU) 2024/2847, that duty was renumbered to Article 14: notify the CSIRT and ENISA of actively exploited vulnerabilities and severe incidents, on the 24-hour / 72-hour / 14-day clocks.

This isn’t legal advice, and no tool makes you compliant. What follows is the plain difference between the ongoing duty to handle vulnerabilities and the specific duty to report one.

Not sure a given product is even in scope? Run the scope check first, it’s free and takes a minute.

Why the article number moved.

The Cyber Resilience Act went through three years of negotiation between the European Commission’s original September 2022 proposal and the text that was actually adopted as Regulation (EU) 2024/2847. Articles were added, split and reordered along the way, and the reporting obligation moved with them. If your source is a 2022 or 2023 write-up, a conference slide, or an early legal briefing, “Article 11” is what it meant, and it’s the same duty that now lives at Article 14.

That renumbering is a footnote. The distinction underneath it isn’t. The CRA gives manufacturers two different obligations that people conflate even once the number is right.

Two duties, not one.

The CRA doesn’t give manufacturers a single “report vulnerabilities” obligation. It gives you an ongoing process duty and, sitting on top of it, a narrow, event-driven notification duty with a name and a clock.

General vulnerability-handling duties compared with the Article 14 reporting duty
AspectVulnerability handling & due diligenceArticle 14 reporting
What it isThe ongoing duty to run a cybersecurity risk assessment, exercise due diligence on integrated components, and handle and remediate vulnerabilitiesThe specific duty to notify a reportable finding to the CSIRT and ENISA
TriggerContinuous: applies across design, development and the whole support periodOnly an actively exploited vulnerability or a severe incident
Where the detail livesA coordinated vulnerability disclosure policy and remediation process, set out in Annex I Part IIThe Single Reporting Platform, in Article 14
ClockNo 24-hour clock: this is standing process, not an event24-hour early warning, 72-hour notification, 14-day final report (one month for a severe incident)
In force fromFull application, 11 December 202711 September 2026

Put plainly: handling is what you run all the time. Reporting is what fires (to the CSIRT and ENISA, via the Single Reporting Platform) when handling turns up something actively exploited or a severe incident hits. Fines for the reporting duties run up to €15M or 2.5% of worldwide annual turnover, which is a reason to get the distinction right rather than report everything “to be safe.”

Two different next steps.

If your question is “does this apply to us, and what would we have to file”, that’s scope and exposure, and the free readiness report answers it against your actual dependency manifest in about 90 seconds, with no email and nothing stored.

If your question is “how do we actually run this on an ongoing basis” (the inventory, the exploitation watch, the awareness record and the submission-ready pack for each reporting stage), that’s the machinery OSPulse builds. See how OSPulse builds the pack.

Frequently asked

Is it Article 11 or Article 14?

Article 14, in the Regulation that actually applies: (EU) 2024/2847. Article 11 was the number for the manufacturer reporting duty in the European Commission’s 2022 proposal. The article moved as the text went through negotiation. If you read early CRA commentary, a 2022 to 2023 blog post, or a slide deck built before the final text, "Article 11" is very likely what it meant by today’s Article 14.

So what’s the difference between "vulnerability handling" and "reporting"?

Vulnerability handling is what you do every day: risk-assess the product, take care with the components you integrate, run a coordinated disclosure policy, and remediate what you find. It never stops and it has no 24-hour clock. Reporting is narrower and event-driven: only when a vulnerability is actively exploited, or a severe incident hits, does the Article 14 clock start and a notification go to the CSIRT and ENISA.

Do I have to report every vulnerability or CVE I fix?

No. The Article 14 reporting duty covers actively exploited vulnerabilities and severe incidents affecting product security, not every CVE you patch. Most of what a vulnerability-handling process finds and fixes never becomes a reporting event.

Am I even in scope for any of this?

If you place a product with digital elements on the EU market (including as a non-EU manufacturer, and including products already on the market), you are. Run the free scope check to see where a specific product lands. It takes about a minute.

Know which duty you’re looking at.

No tool makes you compliant, and this isn’t legal advice, but knowing the right article is the first step to not scrambling on the day one applies.