First obligations from September 2026
Reporting Obligations

Early warning, notification, final report — every deadline in view

The Art. 14 reporting workflow with deadline tracking, security advisories with CSAF publishing, and coordinated vulnerability disclosure

From 11 September 2026, the reporting obligations of the EU Cyber Resilience Act apply: actively exploited vulnerabilities and severe incidents must be reported to the coordinating CSIRT and ENISA — an early warning within 24 hours, a notification within 72 hours, followed by the final report. Kunnus walks you through exactly this sequence: from detection through every deadline to complete documentation, including security advisories in CSAF format.

Art. 14 · 16Legal basis
24 hEarly warning
72 hNotification
CSAFAdvisories
app.kunnus.tech/advisories/KSA-2025-003

Security Advisory KSA-2025-003

Draft
Severity
High
Product
SmartSensor XR
Component
openssl@3.0.13
Advisory Preview

Summary: A heap buffer overflow vulnerability in OpenSSL 3.0.13 affects the SmartSensor XR product line.

Impact: Remote code execution possible via crafted TLS handshake. CVSS 8.1.

Remediation: Update firmware to v3.2.2 or later. Patch available since 2025-01-15.

Key Benefits

Reporting Workflow with Deadline Tracking

From detection through the 24-hour early warning and the 72-hour notification to the final report: every step has a deadline, and Kunnus tracks it.

Security Advisories & CSAF Publishing

Create security advisories for fixed vulnerabilities and publish them in the machine-readable CSAF format — as Annex I Part II No. 4 requires.

Coordinated Vulnerability Disclosure

External reporters submit vulnerabilities via a shareable link — no account needed. Every incoming report is captured and traceably processed.

Complete Documentation

Every report, every deadline, and every decision is documented — reliable evidence for market surveillance and auditors.

Capabilities

Reporting Workflow under Art. 14

Art. 14

Actively exploited vulnerabilities and severe incidents follow the guided sequence: early warning 24 h, notification 72 h, final report — each stage with deadline tracking and status.

Security Advisories with CSAF Publishing

Annex I Part II No. 4

Advisories for fixed vulnerabilities are created in a structured way and published in CSAF format — sharing information about fixed vulnerabilities, as the regulation requires.

Intake of External Reports

Annex I Part II No. 6

External reporters can submit vulnerabilities via a shareable link. Incoming reports are captured, prioritized, and tracked against SLA rules.

CVD Policy from the Policy Library

Annex I Part II No. 5

The template for the coordinated vulnerability disclosure policy is ready in the policy library — adapt, approve, and keep as evidence.

Linked to the Vulnerability Workflow

Reports arise directly from vulnerability management: affected products, components, and remediation status are already captured when the clock starts.

Use Cases

01

Actively Exploited Vulnerability

A vulnerability in a built-in component is being actively exploited. Kunnus instantly shows the affected products, starts the reporting workflow, and tracks the 24-hour early-warning deadline — with all product data already in place.

02

CSAF-Compliant Disclosure

After remediation, the manufacturer publishes a security advisory in CSAF format and informs users — documented and machine-readable.

03

Evidence for Market Surveillance

During an inspection, the complete history of every report is available: timestamps, contents, deadlines, and final reports — no digging through inboxes.

Be ready to report before the clock starts

See how Kunnus guides the Art. 14 reporting workflow — from detection to the final report. We'll walk you through the sequence in a personalized demo.