Reporting readiness depends on fast internal escalation and disciplined timestamps. The organisation should know who can determine manufacturer awareness, who evaluates the Article 14 trigger, who prepares and approves the notification, which product and Member State information is needed, and how corrective or mitigating actions will be updated. Keep actively exploited vulnerability and severe-incident workflows separate because their final-report deadlines differ.
Start With the Article 14 Trigger
Article 14 does not require reporting of every security event. The workflow should first determine whether the manufacturer has become aware of an actively exploited vulnerability contained in the product or a severe incident having an impact on product security. Preserve the facts used for that decision.
Record the Manufacturer Awareness Time
The 24-hour and 72-hour periods run from the manufacturer becoming aware of the reportable vulnerability or incident. The checklist should capture the awareness timestamp, the person or function that established it, and the evidence supporting the timing decision.
Prepare the 24-Hour Early Warning
For both actively exploited vulnerabilities and severe incidents, Article 14 requires an early warning without undue delay and in any event within 24 hours of awareness. The workflow should be designed to submit the early warning even where investigation is still incomplete.
Prepare the 72-Hour Notification
Unless the relevant information has already been provided, the manufacturer must submit the fuller vulnerability or incident notification without undue delay and within 72 hours of awareness. The record should track what information was known, what corrective or mitigating measures were taken and what actions users can take.
Use the Correct Final-Report Deadline
The final-report deadline differs by trigger. For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective or mitigating measure is available. For a severe incident, the final report is due within one month after the 72-hour incident notification, unless the relevant information has already been provided.
Route Notifications Through the Single Reporting Platform
Article 14 notifications are submitted through the Single Reporting Platform established under Article 16. The readiness record should identify the responsible reporting users, access arrangements, relevant CSIRT coordinator and the internal backup process if the primary reporter is unavailable.
Capture Product and Geographic Information
The reporting workflow should be able to identify the affected product, versions and, where applicable, Member States in which the manufacturer is aware the product has been made available. Connect the incident record to the product inventory so those facts do not have to be reconstructed under deadline pressure.
Keep Technical Investigation and Regulatory Reporting Connected
Incident response may continue for days or weeks after the first regulatory filing. Link investigation updates, root-cause analysis, affected-version findings, mitigations and security updates to the reporting record so later notifications and the final report remain consistent with the technical evidence.
Distinguish Actively Exploited Vulnerability and Severe Incident Records
The two Article 14 triggers have overlapping 24-hour and 72-hour stages but different content and final-report rules. A readiness system should preserve which trigger applies rather than using one generic incident type that can obscure the correct deadline.
Retain Submission Evidence and Decision History
Keep timestamps, submitted content, acknowledgements, internal approvals, sensitivity decisions, user communications, corrective actions and final-report evidence. The record should also preserve decisions not to report where an event was assessed and found not to meet the Article 14 trigger.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.