Step 1: Identify your role
- Manufacturer: the primary mandatory reporter under Article 14.
- Open-source software steward: reports an actively exploited vulnerability to the extent it is involved in product development, and a severe incident to the extent it affects systems it provides for development.
- Importer or distributor: urgently escalates vulnerabilities to the manufacturer and meets its own duties; it should not report as the manufacturer without checking its role.
- Researcher or user: may use voluntary CVD. Manufacturer deadlines do not apply merely because that person found the vulnerability.
Step 2: Identify the occurrence
An actively exploited vulnerability has reliable evidence that a malicious actor exploited it in a system without the owner’s permission. Internal discovery, a published CVE or theoretical exploitability alone is insufficient.
A severe incident negatively affects or could affect the product’s ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions; or has led or could lead to malicious code being introduced or executed in the product or a user’s systems.
The absence of a fix does not stop the clock. If the threshold is uncertain, escalate internally immediately and record the evidence; a help contact does not replace mandatory submission.
From 11 September 2026 the duty also covers products made available on the Union market before the CRA generally applies. Legal basis: CRA Article 14.