EU Cyber Resilience Act
Reporting of exploited vulnerabilities and severe incidents (Articles 14 and 15) – EU Cyber Resilience Act

EU Cyber Resilience Act Art. 14(1): Notifying actively exploited vulnerabilities to the CSIRT and ENISA

A manufacturer that becomes aware of an actively exploited vulnerability in its product must notify it at the same time to the CSIRT designated as coordinator and to ENISA, through the single reporting platform of Article 16. Applies from 11 September 2026, including to products placed on the market before 11 December 2027 (Article 69(3)).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 1 control

  • 5.5 Contact with authorities

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Reporting of exploited vulnerabilities and severe incidents (Articles 14 and 15) – EU Cyber Resilience Act

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.