EU Cyber Resilience Act
Reporting of exploited vulnerabilities and severe incidents (Articles 14 and 15) – EU Cyber Resilience Act

EU Cyber Resilience Act Art. 14(7): Submitting through the right Member State end-point

Notifications go through the single reporting platform using the end-point of the coordinating CSIRT of the Member State of the manufacturer's main establishment in the Union, meaning where cybersecurity decisions on its products are mainly taken or, failing that, its largest EU establishment by employees. A manufacturer with no EU main establishment uses, in order, the Member State of the authorised representative acting for most of its products, the importer placing most of them, the distributor making most available, or where most users are located.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Reporting of exploited vulnerabilities and severe incidents (Articles 14 and 15) – EU Cyber Resilience Act

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.