This page reflects our reading of Cyber Resilience Act, Article 14 and related definitions as of . It is not legal advice. Review process.
Terms below marked with a source are the regulation's own vocabulary. Terms marked Declara's own are this product's classification, not a legal category — using them in conversation with a regulator or your CSIRT as if they were regulatory terms would be a mistake.
Actively exploited vulnerability
A vulnerability for which reliable evidence exists that malicious code has been executed on a system without the permission of the system owner, by exploiting the vulnerability. Triggers the Article 14 reporting duty.
Source: Cyber Resilience Act, Article 14, checked 2026-09-13.
Severe incident
An incident having an impact on the security of a product with digital elements that meets criteria set out in the Act — the second of the two event types Article 14 covers, alongside actively exploited vulnerabilities.
Source: Cyber Resilience Act, Article 14, checked 2026-09-13.
Manufacturer
The natural or legal person who develops or manufactures a product with digital elements, or has one developed or manufactured, and markets it under their own name or trademark. The reporting duty in Article 14 falls on the manufacturer.
Source: Cyber Resilience Act, Article 14, checked 2026-09-13.
CSIRT
Computer Security Incident Response Team — the national body a manufacturer reports to, alongside ENISA, when the Article 14 duty is triggered.
Source: Cyber Resilience Act, Article 14, checked 2026-09-13.
SRP
The Single Reporting Platform — the one platform ENISA runs for filing all three Article 14 stages, to your CSIRT and ENISA at once. It's a web form; there's no API today.
Source: ENISA CRA Single Reporting Platform FAQ, checked 2026-09-13.
Early warning
The first Article 14 stage — a brief notice filed within 24 hours of becoming aware of an actively exploited vulnerability or severe incident.
Source: Cyber Resilience Act, Article 14, checked 2026-09-13.
Notification
The second stage — filed within 72 hours of the same awareness point, with more detail than the early warning.
Source: Cyber Resilience Act, Article 14, checked 2026-09-13.
Final report
The third and closing stage. Its deadline differs by event type: 14 days from a corrective measure becoming available for a vulnerability, or 1 calendar month from the notification's submission for an incident.
Source: Cyber Resilience Act, Article 14, checked 2026-09-13.
VEX
Vulnerability Exploitability eXchange — a document format for stating whether a product is actually affected by a known vulnerability in one of its components. Declara reads OpenVEX documents and CycloneDX BOMs carrying vulnerability analysis blocks.
Tier (A/B/C)
Declara's own classification, not a regulatory term and not a CVSS severity rating. Tier A is the only tier that raises an alert — a component that's in the KEV catalogue or has a high EPSS exploitation-probability score. Tier B and C are recorded but don't interrupt anyone. See Understand your first alert for how tiers are assigned.