Definition

Final report

The last Article 14 stage: 14 days after a corrective measure for vulnerabilities, one month after the notification for incidents.

For an actively exploited vulnerability, a final report is due no later than 14 days after a corrective or mitigating measure is available, with a description of the vulnerability, its severity and impact, information on the exploiting actor where available, and details of the security update or other corrective measures. For a severe incident, the final report is due within one month after the 72-hour notification, with a detailed description of the incident, the type of threat or root cause and the mitigation measures applied. The two triggers differ; calendar-month arithmetic applies to the incident case.

Reference: Art. 14(2)(c) and 14(4)(c) · Regulation (EU) 2024/2847 on EUR-Lex

Updated 2026-09-12 · Paraphrase for orientation, not legal advice.

Related terms

See the term as a workflow.

Vellaci turns each of these definitions into a record with an owner, a timestamp and evidence.