OBL-ART14-03Binding
Submit a final vulnerability report to ENISA within 14 days
- Van toepassing op
- Manufacturer
- Bronvermeldingen
- Art. 14(3)Art. 14(5)
- Productklassen
- default, important-class-i, important-class-ii, critical
Last reviewed
Eenvoudige taal
You have 14 days from first knowing about an active bug to send ENISA a full report. By now you need the full story: what the bug was, how bad, and how you fixed it. This is step three of the chain: 24 hours, then 72 hours, then 14 days.
Legal text
Article 14(3) of Regulation (EU) 2024/2847 requires that, no later than 14 days after becoming aware of an actively exploited vulnerability, manufacturers shall submit a final report to ENISA containing:
- A complete description of the vulnerability, including its severity and impact
- Where applicable: the threat actor(s) involved (if known and shareable)
- Information on the corrective or mitigating measures taken
- Whether the vulnerability has been publicly disclosed
- The CVE assigned (or justification for why no CVE was assigned)
Article 14(5) specifies that the report is submitted via the ENISA single reporting platform.
Effective date
This obligation applies from 11 September 2026.
Required final report content
- Complete vulnerability description — full technical analysis
- Root cause analysis — where the vulnerability originated
- CVSS score — final, re-assessed if needed after full analysis
- Affected versions — all product versions and variants in scope
- CVE identifier — CVE number assigned by a CNA, or reason none was assigned
- Remediation deployed — update version number, release date, delivery mechanism
- User notification — description of how users were informed and timeline
- Public disclosure status — whether a security advisory was published and where
- Threat actor information — if known, whether a specific actor is exploiting
The three-step Art. 14 reporting chain
| Step | Deadline | Status |
|---|---|---|
| Early warning (OBL-ART14-01) | 24 hours | Awareness confirmed |
| Detailed notification (OBL-ART14-02) | 72 hours | Technical details available |
| Final report | 14 days | Complete analysis and remediation |
Evidence you may need
- Timestamped final report submission from ENISA platform
- CVE assignment record
- Published security advisory
- User notification records
- Internal incident postmortem or root-cause analysis document