Regulation (EU) 2024/2847 · Article 14 ·Applies from 11 September 2026

CRA reporting deadlines and notification drafter

Article 71 says the CRA applies from 11 December 2027 — and then makes Article 14 an exception, bringing the reporting duties forward to 11 September 2026. Fifteen months earlier. From that date a manufacturer who becomes aware of an actively exploited vulnerability, or of a severe incident affecting the security of a product with digital elements, has 24 hours to send an early warning and 72 hours to send the notification. This free tool works out which clock is running and drafts what Article 14 requires you to say at each stage. It does not file anything, and it does not decide for you whether an incident is severe.

5 FREE DOCUMENTS · RUNS IN YOUR BROWSER · NOTHING UPLOADED

What are you reporting

The product and the clock

Runs entirely in your browser — nothing you enter is uploaded or stored on a server while you generate.

This drafts content. It does not file anything. Article 14(7) requires notifications to go through the single reporting platform of Article 16, to the electronic notification end-point of the CSIRT designated as coordinator in the Member State of your main establishment, and to be simultaneously accessible to ENISA — and which CSIRT that is turns on facts only you hold. Article 14(6) lets that CSIRT ask you for an intermediate report, so three stages is the floor and not the ceiling. Article 14(8) is a separate duty to inform impacted users. Article 14(10) lets the Commission fix the format of these notifications by implementing act; none is reflected here, so this follows the Article's own wording. Informational only, not legal advice.
LIVE PREVIEW · NOTIFICATION DRAFT