By the 72-hour stage, Article 14 expects more substance than the initial early warning but does not require the investigation to be complete. The exact content differs between an actively exploited vulnerability and a severe incident, and the reporting process continues afterwards toward the applicable final report.
The 72-Hour Notification Is the Second Reporting Stage
Article 14 follows a staged reporting model. After the 24-hour early warning, the manufacturer submits a fuller notification without undue delay and in any event within 72 hours after becoming aware of the qualifying event, unless the relevant information has already been provided. The 72-hour stage is therefore not a new clock beginning after the early warning. Both the 24-hour and 72-hour periods are tied to manufacturer awareness. Organisations should calculate both deadlines immediately when the Article 14 trigger is established rather than waiting for the early-warning submission before scheduling the next regulatory task.
- The 72-hour period runs from manufacturer awareness.
- It does not begin when the 24-hour warning is submitted.
- Submit without undue delay and no later than the statutory outer limit.
- Prepare the 72-hour notification while the technical investigation continues.
The Vulnerability Notification Describes the Product, Exploit and Vulnerability
For an actively exploited vulnerability, Article 14(2)(b) requires general information, as available, about the product with digital elements concerned and the general nature of the exploit and vulnerability. The manufacturer also provides corrective or mitigating measures already taken and corrective or mitigating measures that users can take. Where applicable, the manufacturer indicates how sensitive it considers the notified information to be. The phrase as available is important because the investigation may still be developing. The manufacturer should provide a useful and accurate operational picture without inventing certainty or delaying the notification while waiting for every technical detail.
- Identify the affected product.
- Describe the general nature of the exploit.
- Describe the general nature of the vulnerability.
- Describe corrective or mitigating measures already taken.
- Describe actions users can take.
- Indicate information sensitivity where applicable.
The Severe-Incident Notification Includes an Initial Assessment
For a severe incident, Article 14(4)(b) requires general information, where available, about the nature of the incident and an initial assessment of the incident. It also requires information about corrective or mitigating measures already taken and measures users can take. Where applicable, the manufacturer indicates how sensitive the notified information is considered to be. The initial assessment should reflect the best supported view at that stage, including the known scope, affected functions or security properties and relevant technical findings. It should not be presented as a final forensic conclusion where uncertainty remains.
- Describe the nature of the incident.
- Provide the initial assessment available at that time.
- Describe corrective or mitigating measures already taken.
- Describe measures users can take.
- Identify sensitive information where applicable.
- Clearly separate confirmed facts from unresolved questions.
The 72-Hour Stage Requires More Than the Early Warning
The early warning is designed to alert the regulatory system quickly, while the 72-hour notification provides a more developed operational picture. This distinction should be reflected in the manufacturer's internal workflow. The investigation team should continue collecting product and version information, exploitation or incident evidence, scope, mitigation status and customer actions immediately after the early warning is submitted. The reporting owner can then transform those findings into the 72-hour dataset. Reusing the early-warning text without adding the information specifically expected at the second stage can leave the notification incomplete.
- Continue investigation immediately after the early warning.
- Update affected product and version information.
- Update scope and mitigation information.
- Add the specific Article 14 information required at 72 hours.
- Do not merely resubmit the 24-hour warning unchanged.
Available Information Can Still Contain Uncertainty
Article 14 does not require a finished technical investigation within 72 hours. Vulnerability investigations may still be determining exploitation paths, affected configurations or malicious-actor information. Incident investigations may still be assessing root cause, scope and downstream effects. The manufacturer should nevertheless provide the required information that is available and accurately communicate the current state of the assessment. A disciplined notification distinguishes confirmed facts, reasonable assessments and unresolved questions. This reduces the risk of either delaying the submission or presenting speculative information as certainty.
- Use confirmed facts where available.
- Label preliminary assessments appropriately.
- Identify important unresolved questions.
- Update the notification as the investigation develops where the platform permits.
- Preserve evidence supporting material changes.
Mitigation Information Is Part of the Notification
Both 72-hour reporting paths ask for corrective or mitigating measures already taken and measures users can take. This means regulatory reporting cannot be isolated from engineering, vulnerability remediation, support and customer communication. The reporting owner needs current information about configuration changes, containment actions, patches, workarounds, service-side controls and other measures that reduce risk. User actions should be practical and tied to the affected products and versions. Where no corrective measure is yet available, the notification should accurately reflect the current position rather than imply that a fix already exists.
- Track corrective measures taken by the manufacturer.
- Track temporary mitigating measures.
- Identify practical measures users can deploy.
- Keep mitigation guidance aligned with affected product versions.
- Update the record when a corrective measure becomes available.
The 72-Hour Notification Does Not End Article 14 Reporting
After the 72-hour notification, the manufacturer remains responsible for the later reporting stages. For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, the final report is due within one month after submission of the 72-hour incident notification. In addition, the CSIRT designated as coordinator may request an intermediate report on relevant status updates where necessary. Organisations should therefore maintain a regulatory case owner until the final report is submitted rather than closing the Article 14 task immediately after the 72-hour stage.
- Keep the Article 14 case open after 72 hours.
- Track the applicable final-report deadline.
- Be prepared for an intermediate-report request.
- Continue recording mitigation and investigation changes.
- Coordinate the regulatory record with user communication.
Build a 72-Hour Evidence Package During the First Day
The best time to start preparing the 72-hour notification is during the first 24 hours. A standard evidence package can capture the product and versions, Article 14 trigger, incident or exploit description, awareness timestamp, affected regions where relevant, technical evidence, current scope, mitigations, user actions, information-sensitivity assessment and open investigation questions. Each field can be updated as facts develop. This avoids creating the 72-hour notification from scratch near the deadline and gives legal, security and product teams a shared operational record. The same package can later support intermediate and final reporting.
- Open the 72-hour evidence record when the Article 14 case begins.
- Assign owners for technical, legal and product information.
- Update fields continuously rather than waiting for the deadline.
- Track which statements are confirmed and which remain preliminary.
- Carry the evidence record forward into later reporting stages.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.