# CRA Article 14 — Final Report

> **Purpose**: Closing report of an Actively Exploited Vulnerability or Severe Incident.  
> **Deadline**:  
> · **Vulnerabilities**: no later than **14 days** after a corrective / mitigating measure becomes available.  
> · **Severe incidents**: within **1 month** after the initial notification.  
> **Precondition**: Early Warning and 72-hour Notification have already been submitted.  
> **Source**: ENISA SRP FAQ Q16 (v. 03/08/2026). Fields marked **X = Obligatory**, **I = Obligatory if info available**, **C = Copied from previous step and updatable**, **O = Optional**.

---

## 1 · Metadata (copied — update if needed)

| # | Field | Value |
|---|---|---|
| 1 | Notification type | *Vulnerability / Incident* |
| 2 | Notification level | **Final Report** |
| 7 | Name of manufacturer / OSS steward | |
| 8 | Product | |
| 9 | Product Type | |
| 10 | Product Category (Annex III / IV) | |
| 11 | Member States where product available | |
| 12 | Title | |

---

## 2 · Vulnerability — final content

| # | Field | Value |
|---|---|---|
| v21 | Date corrective / mitigating measure became available (UTC) | *YYYY-MM-DD* |
| v22 | Full description of the vulnerability | |
| v23 | a. Severity of the vulnerability | *CVSS v3.1 base score & vector; or equivalent rating* |
| v24 | b. Impact of the vulnerability | *confidentiality / integrity / availability breakdown; blast radius* |
| v25 | Malicious actor that has exploited / is exploiting the vulnerability (**I**) | *actor group, TTPs, indicators — only if confirmed* |
| v26 | Details on the security update / corrective measures available | *release notes, patch level, signature status, rollback protection* |

---

## 3 · Incident — final content

*Fill only if this notification concerns an incident, not a vulnerability.*

| # | Field | Value |
|---|---|---|
| i21 | Severity of the incident (CRA Art. 14(5)) | |
| i22 | Detailed severity rationale (impact on availability / authenticity / integrity / confidentiality; introduction / execution of malicious code) | |
| i23 | Impact of the incident | |
| i24 | Type of threat / root cause likely to have triggered the incident | |
| i25 | Applied and ongoing mitigation measures | |

---

## 4 · User communication delivered

- [ ] Impacted users notified — date: *YYYY-MM-DD*
- [ ] Public advisory published — URL: *https://…*
- [ ] Distribution channels used: *email / in-product / vendor portal / social / partner network*

---

## 5 · Evidence retained (traceable case file)

- [ ] Awareness timestamp
- [ ] All draft & submitted notifications (Early Warning, 72 h, Final)
- [ ] Intermediate updates requested by the CDaC
- [ ] Patch / update artifact & signature
- [ ] Verification test results
- [ ] User notification artefacts

---

## 6 · Approvals

| Role | Name | Signed off |
|---|---|---|
| Primary AR | | |
| Product Security Lead | | |
| Engineering Lead | | |
| Legal / Compliance | | |
| PR / Customer Comms | | |

---

*Template compiled by NexTech.Law from ENISA SRP FAQ Q16 and CRA Art. 14(2)(c). General guidance only — not legal advice. Final Reports are non-editable in the SRP after submission — review carefully before sending.*
