Kilde › Guides › CRA › Notifying users under Article 14(8): t…

Notifying users under Article 14(8): the duty beyond the authorities

Current to 26 August 2026 · updates land in the changelog.

Filing with the CSIRT and ENISA is not the end of the communication duty. Article 14(8) adds a second audience: the people using the product.

What the duty says

After becoming aware of an actively exploited vulnerability or a severe incident, the manufacturer must inform the impacted users — and, where appropriate, all users — of the product about the vulnerability or incident and, where necessary, about risk-mitigating and corrective measures they can deploy. The judgement calls (impacted vs all; what counts as necessary detail) are the manufacturer's to make and to be able to defend.

The backstop that concentrates minds

If the manufacturer fails to inform users in a timely manner, the notified CSIRT can do it instead. That backstop changes the calculus: silence does not keep the matter quiet, it merely hands the messaging to an authority — on their timing and in their words.

Doing this well under time pressure

User notification lands mid-crisis, alongside the 72-hour notification, and it is customer-facing where the authority filings are not. The practical preparation is a pre-approved template family: what happened, who is affected, what to do now, where fixes land — written calmly in advance, reviewed by whoever owns customer communication, with the send channels (in-product, email, advisory page) decided before they are needed.

Related guides

Quick answers

Does the CRA require telling users about vulnerabilities?
Yes — Article 14(8) requires manufacturers to inform impacted users (and where appropriate all users) about an actively exploited vulnerability or severe incident, including mitigations and corrective measures where necessary.
What happens if a manufacturer doesn't notify users?
The CSIRT that received the report may inform the users itself if the manufacturer fails to do so in a timely manner — the message goes out either way.
Be reporting-ready before 11 September 2026.

The CRA Reporting-Ready Pack: the staged 24h / 72h / final-report runbook and templates, vulnerability-vs-incident triage worksheet, CSIRT-routing and main-establishment worksheet, platform registration runbook, CVD policy and evidence log — built from the regulation and the ENISA platform guides, with pinpoint citations.

Get the pack — US$390 Free 4-page sample (PDF)

Instant download · 14-day unconditional refund · single-organisation licence · full product page

General information only — not legal advice, and never a conformity assessment. Whether a specific product falls in a listed category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, and reporting-platform mechanics are ENISA-published material marked subject to change. Sources are Regulation (EU) 2024/2847 (CELEX 32024R2847; Annex III/IV item texts read verbatim from EUR-Lex) and our audited kit research. © 2026 Kilde.

Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com