You already report under NIS2. Is Article 14 the same report?
The short answer
No. They are two duties with two triggers and two sets of recipients, and they look alike because both copied the same 24-hour and 72-hour structure. Filing one does not discharge the other. If both apply to you, both apply to you — and they will often be set off by different events, not by the same one twice.
Where they differ
| CRA, Article 14 | NIS2, Article 23 | |
|---|---|---|
| Who it binds | Manufacturers of products with digital elements, wherever they are established, if the product is made available in the EU. | Essential and important entities operating in the listed sectors, judged by what the organisation does — not by what it ships. |
| What triggers a report | An actively exploited vulnerability in your product, or a severe incident having an impact on the security of your product. | A significant incident affecting the services the entity provides. |
| Early warning | 24 hours from becoming aware. | 24 hours from becoming aware. |
| Notification | 72 hours from becoming aware. | 72 hours from becoming aware. |
| Final report | Vulnerability: 14 days after a fix becomes available. Incident: one month after the notification was submitted. | One month after the incident notification. |
| Where it goes | The coordinating CSIRT and ENISA, through the Single Reporting Platform. | The national CSIRT or competent authority, through whatever channel your Member State designates. |
| How it reaches you | A Regulation. It applies directly, identically, in every Member State. | A Directive. It reaches you through your national transposition, and the details differ by country. |
The Article 14 column is the rule this product implements.Art. 14(1)Art. 14(2)The NIS2 column is summarised from the DirectiveNIS2 Art. 23 and is not what we compute against.
Why one company can owe both
NIS2 asks what your organisation is. The CRA asks what your product is. A company can be both things at once without any contradiction: a vendor that ships an on-premise agent and also operates a managed service for its customers is a manufacturer under the CRA and may be an important entity under NIS2. The agent being exploited in the field and your own service being knocked over are different events, and each has its own recipient.
The case that looks like double reporting
One event genuinely can set off both: someone exploits a vulnerability in the product you ship, and the same flaw is used against the service you operate. That is still two reports, because they say different things to different readers — one is “the product we sold you is being attacked”, the other is “the service we run for you was affected”.
What we do not tell you
Whether your Member State will accept a single submission that satisfies both is a question about your national transposition, and it is not one we answer. The CRA route is fixed — the coordinating CSIRT and ENISA, through the Single Reporting PlatformArt. 14(1) — while the NIS2 route is whatever your country designated. Ask your CSIRT, or your counsel, before assuming one filing covers both. We would rather say this than guess on your behalf.
If you are working out whether Article 14 applies at all
The scope check answers that in five questions, with the article behind each part of the verdict and the authority your reports would go to. It says nothing about NIS2.
If it does apply, the next question is which authority receives the filing — every member state’s CSIRT, and the rule for picking yours.
The NIS2 summary on this page is orientation, not advice, and NIS2 reaches you through your national law rather than the Directive text. This product implements the Cyber Resilience Act only. It is not legal advice, and you remain the party responsible for reporting under either.