Kilde › Guides › CRA › The CRA final report: 14 days or one m…
Current to 26 August 2026 · updates land in the changelog.
The final report is the most misquoted deadline in Article 14. The two tracks measure it from different events, and neither of them is “from awareness”.
For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective or mitigating measure is available. The clock hangs off the remedy, not the discovery — a widely repeated misreading says “14 days after awareness”, which would make the duty impossible whenever a fix takes longer than two weeks. It covers a description of the vulnerability including its severity and impact, information on any malicious actor that has exploited it where available, and details of the security update or other corrective measures made available.
For a severe incident, the final report is due within one month after the 72-hour notification — this one hangs off the previous filing, not off the remedy. It covers a detailed description of the incident including severity and impact, the type of threat or root cause likely to have triggered it, and applied and ongoing mitigation measures.
Under the ENISA platform's published mechanics (subject to change), the final report is non-editable once submitted. The earlier stages copy forward and update; the final report closes the record. That argues for treating it as a reviewed document with sign-off, not a form filled at speed — and for keeping the underlying evidence log tidy from hour zero.
The CRA Reporting-Ready Pack: the staged 24h / 72h / final-report runbook and templates, vulnerability-vs-incident triage worksheet, CSIRT-routing and main-establishment worksheet, platform registration runbook, CVD policy and evidence log — built from the regulation and the ENISA platform guides, with pinpoint citations.
Get the pack — US$390 Free 4-page sample (PDF)Instant download · 14-day unconditional refund · single-organisation licence · full product page
General information only — not legal advice, and never a conformity assessment. Whether a specific product falls in a listed category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, and reporting-platform mechanics are ENISA-published material marked subject to change. Sources are Regulation (EU) 2024/2847 (CELEX 32024R2847; Annex III/IV item texts read verbatim from EUR-Lex) and our audited kit research. © 2026 Kilde.
Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com