compliance-ownerauditorP0Updated
Was this page helpful?

This page reflects our reading of Cyber Resilience Act, Article 14 and related definitions as of . It is not legal advice. Review process.

Terms below marked with a source are the regulation's own vocabulary. Terms marked Declara's own are this product's classification, not a legal category — using them in conversation with a regulator or your CSIRT as if they were regulatory terms would be a mistake.

Actively exploited vulnerability

A vulnerability for which reliable evidence exists that malicious code has been executed on a system without the permission of the system owner, by exploiting the vulnerability. Triggers the Article 14 reporting duty.

Source: Cyber Resilience Act, Article 14, checked 2026-09-13.

Severe incident

An incident having an impact on the security of a product with digital elements that meets criteria set out in the Act — the second of the two event types Article 14 covers, alongside actively exploited vulnerabilities.

Source: Cyber Resilience Act, Article 14, checked 2026-09-13.

Manufacturer

The natural or legal person who develops or manufactures a product with digital elements, or has one developed or manufactured, and markets it under their own name or trademark. The reporting duty in Article 14 falls on the manufacturer.

Source: Cyber Resilience Act, Article 14, checked 2026-09-13.

CSIRT

Computer Security Incident Response Team — the national body a manufacturer reports to, alongside ENISA, when the Article 14 duty is triggered.

Source: Cyber Resilience Act, Article 14, checked 2026-09-13.

SRP

The Single Reporting Platform — the one platform ENISA runs for filing all three Article 14 stages, to your CSIRT and ENISA at once. It's a web form; there's no API today.

Source: ENISA CRA Single Reporting Platform FAQ, checked 2026-09-13.

Early warning

The first Article 14 stage — a brief notice filed within 24 hours of becoming aware of an actively exploited vulnerability or severe incident.

Source: Cyber Resilience Act, Article 14, checked 2026-09-13.

Notification

The second stage — filed within 72 hours of the same awareness point, with more detail than the early warning.

Source: Cyber Resilience Act, Article 14, checked 2026-09-13.

Final report

The third and closing stage. Its deadline differs by event type: 14 days from a corrective measure becoming available for a vulnerability, or 1 calendar month from the notification's submission for an incident.

Source: Cyber Resilience Act, Article 14, checked 2026-09-13.

VEX

Vulnerability Exploitability eXchange — a document format for stating whether a product is actually affected by a known vulnerability in one of its components. Declara reads OpenVEX documents and CycloneDX BOMs carrying vulnerability analysis blocks.

Tier (A/B/C)

Declara's own classification, not a regulatory term and not a CVSS severity rating. Tier A is the only tier that raises an alert — a component that's in the KEV catalogue or has a high EPSS exploitation-probability score. Tier B and C are recorded but don't interrupt anyone. See Understand your first alert for how tiers are assigned.