compliance-ownerP0Updated
Was this page helpful?

This page reflects our reading of Cyber Resilience Act, Article 14(2) as of . It is not legal advice. Review process.

You have 72 hours from the moment you became aware of the vulnerability or incident to submit the notification — the same awareness timestamp that started your 24-hour early warning clock, not a new one starting from when the early warning was filed.

Before you start

Steps

  1. Open the case. It shows early_warning_submitted and a countdown for the notification.
  2. Click Start notification. The case moves to notification_drafting.
  3. Declara pre-fills what it can from your product and case data, including anything carried over from the early warning. Review every field — pre-filled is not the same as correct, and this is also where you'd carry forward any correction to information you gave in the early warning.
  4. Click Generate packet. You get an HTML view and a PDF, both from the same data.
  5. Open the CRA Single Reporting Platform and copy the packet fields into the SRP web form yourself. Declara does not submit to the SRP automatically — there is no SRP API today.
  6. Once submitted on the SRP, return to the case and click Mark submitted. You'll be asked for the SRP reference number, or a note if you filed outside the SRP for an exceptional reason. The case won't let you mark submitted with neither.

What you should see

The case now shows notification_submitted. For an incident case, this is also the moment the final report's one-month clock starts — it's the only deadline in the whole sequence that doesn't run from awareness. For a vulnerability case, the final report instead waits on a fix becoming available; see File the final report for that distinction.

There's no penalty state in the product — the case shows overdue instead of a countdown. File as soon as you can; the regulation requires "without undue delay," not a hard cutoff that voids a late filing. See What to do if you're already overdue.