CRA Reporting Command Center
A single screen for the worst day.
When a reviewer confirms that an event is reportable under Article 14, Vellaci opens a reporting case: awareness time, case type, product, owner and server-computed deadlines in your timezone. Everything the assigned representative needs — the 24-hour early warning, the 72-hour notification, the final report, the evidence and the submission record — is on one page.
Regulatory timing: CRA Article 14 reporting obligations apply from 11 September 2026. The CRA’s general application date is 11 December 2027. These reporting workflows do not determine whether a particular event is legally reportable. How SRP submission works →
Human confirmation first
Vellaci may flag a vulnerability as potentially reportable (for example a CISA KEV listing on a component you ship). A named reviewer confirms or rejects with a rationale before any timer starts.
Server-side deadline engine
Deadlines are persisted with the rule version, source timestamp and timezone. Statuses (upcoming, due soon, critical, overdue) and alerts are computed by background jobs, never only in the browser.
Staged, prefilled forms
Early warning, 72-hour notification and final report share facts you already recorded. Required, recommended and missing fields are labelled against the Article 14 content requirements.
Submission-ready content
Copy the formatted notification or export an evidence package. Submission through the ENISA SRP is recorded with time, submitter, reference and receipt.
Immutable revisions
Every save creates a hashed revision. The revision marked as submitted is frozen; later edits never alter it, and amendments are linked to it.
Final report triggers
For exploited vulnerabilities the 14-day timer starts when a corrective measure is available; for incidents, one calendar month after the 72-hour notification. Two case types, two triggers, no guesswork.
The three stages
What Article 14 asks for at each step.
| Stage | Deadline | Minimum content | In Vellaci |
|---|---|---|---|
| Early warning | 24 h from awareness | Existence of an actively exploited vulnerability or severe incident; whether malicious or unlawful acts are suspected; Member States where the product is made available, where applicable. | Prefilled from the vulnerability or incident record; Member States from the product's market data. |
| Notification | 72 h from awareness | General information on the product; nature of the vulnerability or incident; initial assessment; corrective or mitigating measures taken and that users can take; sensitivity indication where relevant. | Staged form with required/recommended/missing indicators; reuses early-warning facts. |
| Final report — vulnerability | 14 days after a corrective measure is available | Description of the vulnerability, severity and impact; information on the exploiting actor where available; details of the security update or corrective measure. | Timer starts when a fixed version is recorded on the finding. |
| Final report — incident | 1 calendar month after the notification | Detailed description of the incident, severity and impact; type of threat or root cause likely to have triggered it; mitigation measures applied and ongoing. | Calendar-month arithmetic in your timezone (31 Jan → 28/29 Feb, not +30 days). |
Summary of Article 14(2)–(5) and 14(8) of Regulation (EU) 2024/2847 for orientation. The regulation text and the ENISA platform's own field definitions govern; Vellaci's forms are updated as ENISA publishes implementing detail.
Escalation
Alerts that mean something.
Configurable thresholds — half of the window elapsed, 6 h, 3 h, 1 h remaining, overdue — go to the case owner, the assigned representative and compliance leads by e-mail, in-app and, on enterprise plans, to Slack, Microsoft Teams, PagerDuty or a webhook. No noise for provisional timers; nothing fires until a human has confirmed reportability.
Runbook
Who is the assigned representative, who has SRP access, who decides awareness — captured once and shown on every case.
Continuity sheet
A printable one-page summary of contacts, credentials locations and steps for when the primary owner is unavailable.
Drills
Simulated cases with real clocks and alerts, kept out of live metrics, with a drill report for the readiness file.
Evidence package
Submission record, notification revisions, timeline and attachments exported as a signed ZIP for auditors.
FAQ
Reporting questions, answered plainly.
- When does the 24-hour clock start?
- When the manufacturer becomes aware of the actively exploited vulnerability or the severe incident (Article 14(2) and 14(4)). Vellaci never infers awareness from when a ticket was created: a named reviewer records the awareness timestamp with its timezone, and the early warning, notification and final-report deadlines are computed server-side from that moment.
- What is the difference between an early warning and a notification?
- The early warning (within 24 hours) is minimal: that an exploited vulnerability or severe incident exists, whether malicious acts are suspected and, where applicable, the Member States concerned. The notification (within 72 hours) adds general information about the product, the nature of the vulnerability or incident, an initial assessment, and corrective or mitigating measures taken or that users can take. Vellaci stages both forms and prefills the second from the first.
- When is the final report due?
- For an actively exploited vulnerability: no later than 14 days after a corrective or mitigating measure is available. For a severe incident: within one month after the 72-hour notification. Vellaci starts each timer from its correct trigger, in calendar-correct arithmetic and in your organisation's timezone.
- Does Vellaci submit to ENISA for us?
- No. Notifications are submitted by the manufacturer through the ENISA Single Reporting Platform. Vellaci prepares submission-ready content, tracks the deadlines, and records the submission — time, submitter, platform reference, receipt — as a frozen, hash-chained revision with evidence.
- What if we are unsure whether something is reportable?
- That is a legal judgement your organisation and its advisers make. Vellaci surfaces the signals (CISA KEV listing, EPSS, exploitation evidence, customer reports) and structures the review — not reviewed → potentially reportable → confirmed or not reportable — with rationale, reviewer and timestamp. Rejecting reportability is a recorded decision too.
- Can we rehearse the workflow?
- Yes. Drill mode opens a simulated case with the same clocks, forms, alerts and evidence steps, clearly labelled as a drill and kept out of real reporting metrics. Reporting has been in force since 11 September 2026; if you have not rehearsed yet, run a drill now and one per quarter afterwards.
Read next
- Guide
CRA Article 14 reporting obligations: a practical guide for manufacturers
What must be reported under Article 14 of the Cyber Resilience Act, by whom, to whom and when — the 24-hour early warning, 72-hour notification and final report — and how to operationalise it now that the obligation is in force (since 11 September 2026).
- Guide
CRA reporting timeline: 24 hours, 72 hours and the final report
How the Article 14 deadlines are computed, where the final-report trigger sits for vulnerabilities versus incidents, how calendar months and daylight-saving time behave, and three worked examples.
- Guide
Incident or vulnerability? How the CRA treats the two reportable events
Actively exploited vulnerabilities and severe incidents share the 24-hour and 72-hour steps but differ in definition, notification content and final-report trigger. How to classify an event, when one becomes the other, and what to record.
- Docs
Reporting cases and deadlines
24h early warning, 72h notification, final report.
- Docs
Runbook and drills
Organisation readiness and simulated exercises.
- Free tool
CRA deadline calculator
24-hour, 72-hour and final-report deadlines from an awareness time, using Vellaci's deadline engine.
Run a reporting drill before the real thing.
Open a demo case and walk your team through the 24-hour workflow.