Early warning, notification, final report — every deadline in view
The Art. 14 reporting workflow with deadline tracking, security advisories with CSAF publishing, and coordinated vulnerability disclosure
From 11 September 2026, the reporting obligations of the EU Cyber Resilience Act apply: actively exploited vulnerabilities and severe incidents must be reported to the coordinating CSIRT and ENISA — an early warning within 24 hours, a notification within 72 hours, followed by the final report. Kunnus walks you through exactly this sequence: from detection through every deadline to complete documentation, including security advisories in CSAF format.
Security Advisory KSA-2025-003
DraftSummary: A heap buffer overflow vulnerability in OpenSSL 3.0.13 affects the SmartSensor XR product line.
Impact: Remote code execution possible via crafted TLS handshake. CVSS 8.1.
Remediation: Update firmware to v3.2.2 or later. Patch available since 2025-01-15.
Key Benefits
Reporting Workflow with Deadline Tracking
From detection through the 24-hour early warning and the 72-hour notification to the final report: every step has a deadline, and Kunnus tracks it.
Security Advisories & CSAF Publishing
Create security advisories for fixed vulnerabilities and publish them in the machine-readable CSAF format — as Annex I Part II No. 4 requires.
Coordinated Vulnerability Disclosure
External reporters submit vulnerabilities via a shareable link — no account needed. Every incoming report is captured and traceably processed.
Complete Documentation
Every report, every deadline, and every decision is documented — reliable evidence for market surveillance and auditors.
Capabilities
Reporting Workflow under Art. 14
Art. 14Actively exploited vulnerabilities and severe incidents follow the guided sequence: early warning 24 h, notification 72 h, final report — each stage with deadline tracking and status.
Security Advisories with CSAF Publishing
Annex I Part II No. 4Advisories for fixed vulnerabilities are created in a structured way and published in CSAF format — sharing information about fixed vulnerabilities, as the regulation requires.
Intake of External Reports
Annex I Part II No. 6External reporters can submit vulnerabilities via a shareable link. Incoming reports are captured, prioritized, and tracked against SLA rules.
CVD Policy from the Policy Library
Annex I Part II No. 5The template for the coordinated vulnerability disclosure policy is ready in the policy library — adapt, approve, and keep as evidence.
Linked to the Vulnerability Workflow
Reports arise directly from vulnerability management: affected products, components, and remediation status are already captured when the clock starts.
Use Cases
Actively Exploited Vulnerability
A vulnerability in a built-in component is being actively exploited. Kunnus instantly shows the affected products, starts the reporting workflow, and tracks the 24-hour early-warning deadline — with all product data already in place.
CSAF-Compliant Disclosure
After remediation, the manufacturer publishes a security advisory in CSAF format and informs users — documented and machine-readable.
Evidence for Market Surveillance
During an inspection, the complete history of every report is available: timestamps, contents, deadlines, and final reports — no digging through inboxes.
Related Features
Be ready to report before the clock starts
See how Kunnus guides the Art. 14 reporting workflow — from detection to the final report. We'll walk you through the sequence in a personalized demo.