# CRA Article 14 — Early Warning (24 h)

> **Purpose**: First-stage notification of an Actively Exploited Vulnerability (AEV) or Severe Incident (SI) affecting a product with digital elements.  
> **Deadline**: Without undue delay, in any case **within 24 hours** of the manufacturer becoming aware.  
> **Channel**: ENISA CRA Single Reporting Platform (SRP) — submitted by an Assigned Representative (AR) via EU Login.  
> **Source**: ENISA SRP FAQ Q16 (v. 03/08/2026). Fields marked **X = Obligatory**, **I = Obligatory if information is available**, **O = Optional**.

---

## 1 · Notification metadata

| # | Field | Value |
|---|---|---|
| 1 | Notification type (Vulnerability / Incident) | *e.g. Vulnerability* |
| 2 | Notification level | **24h — Early Warning** |
| 6 | Reporter (AR name & EU Login) | *auto-filled by SRP* |
| 7 | Name of manufacturer / OSS steward | *Your legal entity name* |
| 8 | Product | *Product name (as commercially placed on the EU market)* |
| 9 | Product Type (Default / Important / Critical) | *e.g. Default — CRA Annex III N/A* |
| 10 | Product Category (CRA Annex III / IV) | *e.g. N/A / Annex III Class I §…* |
| 11 | Member States where product available (**I**) | *e.g. AT, DE, FR, IT, NL* |
| 12 | Title | *One-line human-readable title of the vulnerability / incident* |

---

## 2 · Awareness timestamp

- **Date & time of manufacturer awareness (UTC):** *YYYY-MM-DD hh:mm UTC*
- **Source of awareness:** *researcher disclosure / customer report / internal detection / third-party CSIRT / telemetry*
- **Case ID (internal):** *e.g. VULN-2026-0037*

---

## 3 · Additional notes (optional)

*Free-text field. Keep it factual. Do not include PII, exploit code or attribution guesses at this stage.*

---

## 4 · Approvals

| Role | Name | Signed off |
|---|---|---|
| Primary AR | | |
| Product Security Lead | | |
| Legal / Compliance | | |

---

*Template compiled by NexTech.Law from ENISA SRP FAQ Q16. General guidance only — not legal advice.*
