Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

Agent · cyberresiliens-2024-2847-14

Cyberresiliensakten artikel 14: Reporting obligations of manufacturers

Structural tree: the article's own paragraphs, verbatim.

CELEX 32024R2847 · 2026-08-18 · Weight 78 · minimal-risk

ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.

CyberresiliensaktenOfficial source

What this page is
Agent, Cyberresiliensakten artikel 14
Checked against the official source
2026-08-18Current
Responsible publisher
ExploreWorld Legal, editorial deskLiability position

Jurisdiction

The same agent, read through one country's lens.

Inputs

  • in_scopeThe article applies to the situationboolean
  • punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)

Rule tree

  1. If: alla(in_scope = true, punkt = 1)

    Paragraph 1 applies

    1. A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. The manufacturer shall notify that actively exploited vulnerability via the single reporting platform established pursuant to Article 16.

    Paragraph 1

  2. If: alla(in_scope = true, punkt = 2)

    Paragraph 2 applies

    2. For the purposes of the notification referred to in paragraph 1, the manufacturer shall submit:

    Paragraph 2

  3. If: alla(in_scope = true, punkt = 3)

    Paragraph 3 applies

    (a)

    Paragraph 3

  4. If: alla(in_scope = true, punkt = 4)

    Paragraph 4 applies

    an early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available;

    Paragraph 4

  5. If: alla(in_scope = true, punkt = 5)

    Paragraph 5 applies

    (b)

    Paragraph 5

  6. If: alla(in_scope = true, punkt = 6)

    Paragraph 6 applies

    unless the relevant information has already been provided, a vulnerability notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the actively exploited vulnerability, which shall provide general information, as available, about the product with digital elements concerned, the general nature of the exploit and of the vulnerability concerned as well as any corrective o…

    Paragraph 6

  7. If: alla(in_scope = true, punkt = 7)

    Paragraph 7 applies

    (c)

    Paragraph 7

  8. If: alla(in_scope = true, punkt = 8)

    Paragraph 8 applies

    unless the relevant information has already been provided, a final report, no later than 14 days after a corrective or mitigating measure is available, including at least the following:

    Paragraph 8

  9. If: alla(in_scope = true, punkt = 9)

    Paragraph 9 applies

    (i)

    Paragraph 9

  10. If: alla(in_scope = true, punkt = 10)

    Paragraph 10 applies

    a description of the vulnerability, including its severity and impact;

    Paragraph 10

  11. If: alla(in_scope = true, punkt = 11)

    Paragraph 11 applies

    (ii)

    Paragraph 11

  12. If: alla(in_scope = true, punkt = 12)

    Paragraph 12 applies

    where available, information concerning any malicious actor that has exploited or that is exploiting the vulnerability;

    Paragraph 12

  13. If: alla(in_scope = true, punkt = 13)

    Paragraph 13 applies

    (iii)

    Paragraph 13

  14. If: alla(in_scope = true, punkt = 14)

    Paragraph 14 applies

    details about the security update or other corrective measures that have been made available to remedy the vulnerability.

    Paragraph 14

If no rule matches: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.

The article text as read

  1. 11. A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. The manufacturer shall notify that actively exploited vulnerability via the single reporting platform established pursuant to Article 16.
  2. 22. For the purposes of the notification referred to in paragraph 1, the manufacturer shall submit:
  3. 3(a)
  4. 4an early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available;
  5. 5(b)
  6. 6unless the relevant information has already been provided, a vulnerability notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the actively exploited vulnerability, which shall provide general information, as available, about the product with digital elements concerned, the general nature of the exploit and of the vulnerability concerned as well as any corrective or mitigating measures taken, and corrective or mitigating measures that users can take, and which shall also indicate, where applicable, how sensitive the manufacturer considers the notified information to be;
  7. 7(c)
  8. 8unless the relevant information has already been provided, a final report, no later than 14 days after a corrective or mitigating measure is available, including at least the following:
  9. 9(i)
  10. 10a description of the vulnerability, including its severity and impact;
  11. 11(ii)
  12. 12where available, information concerning any malicious actor that has exploited or that is exploiting the vulnerability;
  13. 13(iii)
  14. 14details about the security update or other corrective measures that have been made available to remedy the vulnerability.

Lineage

treatyTFEU art. 288 (förordning)
act32024R2847
chapter
article14
paragraphs14
jurisdictionEuropean Union (EU)
supervisor
national

Interface

callhttps://legal.exploreworldai.com/api/public/v1/agents/cyberresiliens-2024-2847-14/run
methodGET
outputmatched, outcome, trace, missing, hash
Quota60 anrop per minut och adress, utan nyckel
stabilityRegelträdet versioneras. En ändring byter artefakthash, aldrig adress.

Hashes

textsha256:1ab3d81d8b19d3d1bffd00366053ccf9371e60847c61f0016440f7c80a56f7c7
scriptsha256:ce71630f055dd4785d8cf45ac519250ffcc3f05197592be9cb779452c1d63d69
enginesha256:0a4bd50d21f8ec9be383fc091511008b76ad61909cbfb674eab56fe567fbd7a0
agentsha256:4841f1b66ccd725fdedb552056ed56d7e9ae9807d993e78c42b7bf7daee35d70
versionagent-engine-1+legal-2026-08-25 / 4841f1b66ccd725f

Artefacts

No legal advice. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.

Citation: 32024R2847 art. 14, Reporting obligations of manufacturers. ExploreWorld Legal, https://legal.exploreworldai.com/agent/cyberresiliens-2024-2847/artikel-14 (hämtad 2026-08-18, bevis sha256:91e65f9d8be73289, bygge legal-2026-08-25).