Start trial
For open source maintainers

Managed Article 14 reporting of the Cyber Resilience Act

Starting September 11, 2026, the CRA Article 14 requires software maintainers to report actively exploited vulnerabilities and severe incidents to the EU within 24 hours of becoming aware of them. Patchstack provides known exploited vulnerability tracking & managed Article 14 reporting to EU for free.

Funded by the European Union

What is Cyber Resilience Act and Article 14?

Starting from 11th of September 2026, the EU Cyber Resilience Act requires manufacturers of software and connected products to report two things: vulnerabilities that attackers are actively exploiting, and severe security incidents affecting their products.

  • Reports go to national cybersecurity authorities and the EU cybersecurity agency ENISA through a single EU platform
  • The deadlines are tight: an early warning within 24 hours, a fuller notification within 72 hours, and a detailed final report later
  • Manufacturers must also tell affected users what happened and how to protect themselves

Actively exploited vulnerability

A security vulnerability in your software or product that is known to be actively exploited. Even a single proven attack that exploits a vulnerability triggers Article 14 reporting requirement.

Severe incident

An incident such as supply chain compromise or any other severe incident that affects the product availability, authenticity, integrity or that leads to malicious code running in your product or user's system.

What are the reporting deadlines?

Actively exploited vulnerability

24H
24 hoursfrom becoming aware
Early warning notification

Submitted through ENISA, naming the affected EU member states where your product is available.

72H
72 hoursfrom becoming aware
Full vulnerability notification

Covers the product affected, the nature of the exploit, corrective or mitigating measures taken, and what users have to do to stay safe.

14D
14 daysafter a fix is available
Final report

Details severity, impact, any known malicious actor, and the specifics of the fix.

Severe incident

24H
24 hoursfrom awareness
Early warning notification

States whether you suspect unlawful or malicious acts behind the incident.

72H
72 hoursfrom awareness
Incident notification

Includes an initial assessment of the incident and the mitigation measures taken.

1MO
1 monthafter the 72-hour notification
Final post-mortem report

Covers the incident in detail — root cause, and mitigations applied.

Who this applies to

The Cyber Resilience Act Article 14 applies to manufacturers and open source stewards of products/software made available on the EU market. Non-compliance penalties equal to GDPR penalties. Open source stewards are exempt from penalties however EU can still use other means necessary to remove a non-compliant product from the European market.

How does Patchstack help?

Patchstack provides a free-to-access platform for open-source maintainers that:

  • Tracks the active exploitation of individual vulnerabilities, collects evidence, and notifies the maintainer once Article 14 requirements kick in
  • Allows Patchstack to act as the official Assigned Representative (AR) for the maintainer, fulfilling the Article 14 requirements and ensuring that the deadlines for each reporting form are met
  • Provides a single-channel mVDP and a bug bounty program tailored to open-source maintainers
As the largest vulnerability discloser globally, we already have the systems in place to deal with large report volumes
Access to this data helps us develop and launch fast vulnerability mitigation rules to end-users – it's a win-win
Patchstack acts as your assigned representative, submitting Article 14 reports to the EU on your behalf
Securing the web with the support of
GoogleOpenSSFEU

How does the Article 14 reporting service work?

Software vendors can submit Patchstack as their assigned representative for security reporting:

1

Create a free mVDP account

2

Submit your mVDP application, designating Patchstack as your security point of contact

3

Request Article 14 reporting support

What the FAQ

What is Article 14 of the Cyber Resilience Act?
Article 14 is the part of the EU Cyber Resilience Act that defines how and when software vendors must report cybersecurity incidents. Any actively exploited vulnerability, or severe security incident, must be reported to the EU within 24 hours of it becoming publicly known. Vendors submit this information themselves via the ENISA digital platform, or delegate the responsibility to an assigned representative like Patchstack.
When does Article 14 reporting become mandatory?
Article 14 reporting obligations become enforceable on September 11, 2026. From that date, software vendors with users in the EU must report actively exploited vulnerabilities and severe security incidents within 24 hours of them becoming publicly known.
What counts as a "severe incident" under the CRA?
An incident counts as severe when it damages your product's ability to protect the availability, authenticity, integrity or confidentiality of important data or functions, or when it leads to malicious code running in your product or in a user's systems.
What are the penalties for not complying with Article 14?
Breaches of Article 14 reporting obligations can be penalized up to €15 million or 2.5% of worldwide annual turnover, whichever is higher.
What is an "assigned representative" under the CRA?
Instead of reporting incidents to the EU yourself, the Cyber Resilience Act lets you delegate this responsibility to an assigned representative – a third party that handles Article 14 reporting on your behalf. Patchstack offers this to all Patchstack mVDP partners for free: designate Patchstack as your security point of contact and we take care of the reporting.
What is the difference between VDP and mVDP?
VDP stand for Vulnerability Disclosure Program which is usually self-managed. mVDP stands for managed Vulnerability Disclosure Program. This means that Patchstack processes all the vulnerability reports for you, rejects the false ones, provides additional information if needed, and helps validate the patches before release — making it the much more comfortable option.
Do I need a Vulnerability Disclosure Program just for that?
It's not just vulnerability processing. Having a VDP security program is a signal to your users that you take security seriously and your software is trustworthy. Easy reporting motivates more security researchers to look for vulnerabilities and report them via the Patchstack Bug Bounty program to help make your software better and safer. Also, it's a must when it comes to complying with the European Cyber Resilience Act which now requires all businesses in Europe to have an overview of the security state of their software.
How much does mVDP cost?
It's free, but you can customize your mVDP program and ask to set up a bounty pool with custom scopes and rules to motivate security researchers. You can set any bounty pool for your private VDP program, but additional rules and obligations apply to ensure your private program meets industry standards.
What do I need to activate the mVDP?
The first step is to submit your plugin or theme to the mVDP program and provide contact information for technical contacts about reports. To activate the program, your plugin/theme page or vulnerability disclosure policy should include information about the program and where to report vulnerabilities for a particular product – the VDP page we generate for each plugin or theme submitted to the mVDP program.

If you have questions, don't hesitate to reach out via mvdp@patchstack.com.

Let's make the open-source web safer together!