Reporting actively exploited vulnerabilities and severe incidents
Manufacturers must notify EU authorities (via ENISA) when they identify a vulnerability being actively exploited in the wild or experience a severe security incident affecting their products. This requirement ensures that systemic risks to the EU digital ecosystem are centrally tracked and mitigated quickly.
What it means
The intent of this requirement is to eliminate "silent" exploits where a manufacturer knows a product is under attack but fails to inform regulators, leaving other users and authorities blind to the threat. It shifts vulnerability management from a private company process to a regulated public safety obligation.
In practice, this does not apply to every bug or CVE discovered. The reporting trigger is specifically tied to "active exploitation" (the flaw is being used by attackers) or "severe incidents" (events causing significant operational disruption or affecting a large number of users).
The scope covers all products with digital elements placed on the EU market. Manufacturers are responsible for monitoring their products and maintaining a direct line of communication with the relevant European Union agency to report these events without undue delay.
How to meet it
- Establish a Vulnerability Management Process (VMP) that specifically flags whether a vulnerability is being "actively exploited" in the wild.
- Define clear internal criteria for what constitutes a "severe incident," based on factors such as the number of affected users, criticality of the impacted function, and potential for cascading failure.
- Create a dedicated reporting workflow that ensures security analysts can escalate discovery to the compliance or legal lead responsible for regulatory filings.
- Identify the specific EU portals or contact points (via ENISA) used for submitting these notifications to ensure no delay during an actual event.
- Develop standardized internal templates for reports that include product identifiers, nature of the exploit/incident, and planned mitigation steps.
- Implement internal SLAs for notification timelines to ensure "without undue delay" is operationalized into a specific number of hours or days.
Evidence an auditor asks for
- The written Incident Response Plan (IRP) or Vulnerability Disclosure Policy that explicitly references Art. 14 reporting obligations.
- Records of any submitted reports to EU authorities, including timestamps and confirmation receipts.
- Internal risk assessment logs demonstrating how the organization determined whether a specific incident met the "severe" threshold for reporting.
- Documentation of the communication channel established between the technical security team and the regulatory reporting officer.
Common pitfalls
- Confusing general vulnerability disclosure (e.g., publishing a CVE or notifying customers) with the mandatory legal requirement to notify EU authorities.
- Failing to define "severity" objectively, leading to inconsistent reporting where some severe incidents are ignored while minor ones are over-reported.
- Assuming that providing a patch automatically satisfies the reporting requirement; the notification of the exploit must happen regardless of whether a fix is already available.