EU CRA Article 14 cheat sheet
eu-cra-art14 ruleset version 2026.09.1, effective 12/09/2026. See the changelogfor prior versions.
Stages and deadlines
| Stage | Actively Exploited Vulnerability | Severe Incident |
|---|---|---|
| Early Warning | awareness_at + 24h | awareness_at + 24h |
| 72-hour Notification | awareness_at + 72h | awareness_at + 72h |
| Final Report | corrective_measure_available_at + 14d | notif_submitted_at + 1mo |
CDaC selection order
CDaC is the CSIRT designated as coordinator for your case, under CRA Article 16. Work down this list until one applies:
- In general, you should report to the CDaC in the Member State of your main establishment in the EU.
- If this cannot be determined, use the Member State where your establishment with the highest number of employees in the EU is located.
- If you do not have a main establishment in the EU: the Member State where your authorised representative acts on your behalf for the highest number of products with digital elements.
- If this does not apply, the Member State where the importer places the highest number of your products with digital elements on the market.
- If this does not apply, the Member State where the distributor makes the highest number of your products with digital elements available on the market.
- If none of the above applies, the Member State with the highest number of users of your products with digital elements.
Find your country's CSIRT coordinator →
Particular Exceptional Circumstances (PEC)
PEC lets you withhold full 72-hour AEV notification details from wider dissemination when one of these applies:
- A. the notified vulnerability has been actively exploited by a malicious actor and, according to the information available, it has been exploited in no other Member State than the one of the CSIRT designated as coordinator to which the manufacturer has notified the vulnerability; or
- B. that any immediate further dissemination of the notified vulnerability would likely result in the supply of information the disclosure of which would be contrary to the essential interests of that Member State; or
- C. that the notified vulnerability poses an imminent high cybersecurity risk stemming from the further dissemination;