
The CRA clock that is already running
Most teams are still watching December 2027. Article 14 reporting started on 11 September — and the early warning is 24 hours.
Article 14 — actively exploited vulnerabilities, and severe incidents affecting the security of a product with digital elements — has applied since 11 September 2026. ENISA’s Single Reporting Platform is the channel.
- 24hoursEarly warning — to the CSIRT designated as coordinator, and simultaneously to ENISA
- 72hoursFuller notification
- 14daysFinal report, actively exploited vulnerability — from when a corrective or mitigating measure is available
- 1monthFinal report, severe incident — from the 72-hour notification
What most coverage skips
This applies to products already on the market.
Not just what you place on it after December 2027. A unit you shipped three years ago, still in use, still yours to report on — and a product past its support period stays inside Article 14 for as long as it is out there.
That is a different kind of problem from a compliance deadline. It asks whether you can find out what is inside a fielded unit, and whether anyone is on the hook to notice, inside one working day.
The software-side mirror
The FCC Covered List rule asks who produced the logic-bearing parts on your board. Article 14 asks the software-side mirror: what is inside the product you shipped, and can you account for it fast enough to report. Same discipline, different regulator. West, component provenance for market access. At home, whether a 24-hour clock on a fielded unit is operable at all.
US · WestComponent provenance for market accessFCC Covered List · who produced the logic-bearing parts
EU · At homeWhether a 24-hour clock on a fielded unit is operable at allCRA Article 14 · what is inside the product you shippedNorseman does not sell CRA programmes. But if you already treat bill-of-materials truth as infrastructure, that habit is what makes Article 14 workable now the clock has started.
Nothing here is regulatory advice. Builds and placing-on-the-market facts differ.
Sources
- European Commission — Cyber Resilience Act, reporting obligations
- Regulation (EU) 2024/2847, Articles 14, 16, 69(3) and 71(2)
- Commission guidance C(2026) 5252, 27 July 2026
- ENISA Single Reporting Platform, live 11 September 2026
