compliance-ownerP0Updated
Was this page helpful?

This page reflects our reading of Cyber Resilience Act, Article 14(2) as of . It is not legal advice. Review process.

You have 24 hours from the moment you became aware of an actively exploited vulnerability or severe incident to submit an early warning. This page gets you through it.

Before you start

Steps

  1. Open the case from Alerts → your alert → Case.
  2. Click Start early warning. The case moves from open to early_warning_drafting — this starts your visible countdown, it does not start your legal clock. The legal clock started when you became aware; enter that timestamp accurately in Awareness recorded at, even if it's earlier than right now.
  3. Declara pre-fills the early warning fields it can determine from your product and case data. Review each — pre-filled is not the same as correct.
  4. Click Generate packet. You get an HTML view and a PDF, both built from the same data.
  5. Open the CRA Single Reporting Platform and copy the packet fields into the SRP web form yourself. Declara does not submit to the SRP automatically — there is no SRP API today.
  6. Once submitted on the SRP, return to the case and click Mark submitted. You'll be asked for the SRP reference number. If you filed outside the SRP for an exceptional reason, you can instead enter a note explaining why — the case won't let you mark submitted with neither.

What you should see

The case now shows early_warning_submitted and a new countdown for the 72-hour notification. The original 24-hour countdown disappears — it does not turn into a "late" indicator, because at this point you've already filed.

There's no penalty state in the product — the case shows overdue instead of a countdown, and Declara has no way to know whether your CSIRT has already been in contact with you. File as soon as you can; the regulation requires "without undue delay," not a hard cutoff that voids a late filing. See What to do if you're already overdue.