Auditen
Home / Frameworks / Cyber Resilience Act / Reporting actively exploited vulnerabilities and severe incidents
Cyber Resilience Act · Art. 14

Reporting actively exploited vulnerabilities and severe incidents

Manufacturers must notify EU authorities (via ENISA) when they identify a vulnerability being actively exploited in the wild or experience a severe security incident affecting their products. This requirement ensures that systemic risks to the EU digital ecosystem are centrally tracked and mitigated quickly.

What it means

The intent of this requirement is to eliminate "silent" exploits where a manufacturer knows a product is under attack but fails to inform regulators, leaving other users and authorities blind to the threat. It shifts vulnerability management from a private company process to a regulated public safety obligation.

In practice, this does not apply to every bug or CVE discovered. The reporting trigger is specifically tied to "active exploitation" (the flaw is being used by attackers) or "severe incidents" (events causing significant operational disruption or affecting a large number of users).

The scope covers all products with digital elements placed on the EU market. Manufacturers are responsible for monitoring their products and maintaining a direct line of communication with the relevant European Union agency to report these events without undue delay.

How to meet it

Evidence an auditor asks for

  • The written Incident Response Plan (IRP) or Vulnerability Disclosure Policy that explicitly references Art. 14 reporting obligations.
  • Records of any submitted reports to EU authorities, including timestamps and confirmation receipts.
  • Internal risk assessment logs demonstrating how the organization determined whether a specific incident met the "severe" threshold for reporting.
  • Documentation of the communication channel established between the technical security team and the regulatory reporting officer.

Common pitfalls

  • Confusing general vulnerability disclosure (e.g., publishing a CVE or notifying customers) with the mandatory legal requirement to notify EU authorities.
  • Failing to define "severity" objectively, leading to inconsistent reporting where some severe incidents are ignored while minor ones are over-reported.
  • Assuming that providing a patch automatically satisfies the reporting requirement; the notification of the exploit must happen regardless of whether a fix is already available.