Agent · cyberresiliens-2024-2847-14
Cyberresiliensakten artikel 14: Reporting obligations of manufacturers
Structural tree: the article's own paragraphs, verbatim.
CELEX 32024R2847 · 2026-08-18 · Weight 78 · minimal-risk
ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.
CyberresiliensaktenOfficial source
- What this page is
- Agent, Cyberresiliensakten artikel 14
- Checked against the official source
- 2026-08-18Current
- Responsible publisher
- ExploreWorld Legal, editorial deskLiability position
Short answer
What does Cyberresiliensakten Article 14 require, and what outcome does the rule tree give?
Cyberresiliensakten Article 14 is tested here by a deterministic rule tree of 14 rules, built from the article's own conditions. The tree reads your facts and names the outcome that applies, starting with Paragraph 1 applies, carrying paragraph citation, content hash and read date 2026-08-18 against CELEX 32024R2847. The outcome is a machine classification, not a compliance decision.
Cyberresiliensakten Article 14Checked against the publisher 2026-08-18Official text
- Paragraph 1 applies. 1. A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. The manufacturer shall notify that actively exploited vulnerability via the single reporting platform established pursuant to Article 16.
- Paragraph 2 applies. 2. For the purposes of the notification referred to in paragraph 1, the manufacturer shall submit:
- Paragraph 3 applies. (a)
A source reference, not legal advice.
Jurisdiction
The same agent, read through one country's lens.
Inputs
- in_scopeThe article applies to the situationboolean
- punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)
Rule tree
If: alla(in_scope = true, punkt = 1)
Paragraph 1 applies
1. A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. The manufacturer shall notify that actively exploited vulnerability via the single reporting platform established pursuant to Article 16.
Paragraph 1
If: alla(in_scope = true, punkt = 2)
Paragraph 2 applies
2. For the purposes of the notification referred to in paragraph 1, the manufacturer shall submit:
Paragraph 2
If: alla(in_scope = true, punkt = 3)
Paragraph 3 applies
(a)
Paragraph 3
If: alla(in_scope = true, punkt = 4)
Paragraph 4 applies
an early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available;
Paragraph 4
If: alla(in_scope = true, punkt = 5)
Paragraph 5 applies
(b)
Paragraph 5
If: alla(in_scope = true, punkt = 6)
Paragraph 6 applies
unless the relevant information has already been provided, a vulnerability notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the actively exploited vulnerability, which shall provide general information, as available, about the product with digital elements concerned, the general nature of the exploit and of the vulnerability concerned as well as any corrective o…
Paragraph 6
If: alla(in_scope = true, punkt = 7)
Paragraph 7 applies
(c)
Paragraph 7
If: alla(in_scope = true, punkt = 8)
Paragraph 8 applies
unless the relevant information has already been provided, a final report, no later than 14 days after a corrective or mitigating measure is available, including at least the following:
Paragraph 8
If: alla(in_scope = true, punkt = 9)
Paragraph 9 applies
(i)
Paragraph 9
If: alla(in_scope = true, punkt = 10)
Paragraph 10 applies
a description of the vulnerability, including its severity and impact;
Paragraph 10
If: alla(in_scope = true, punkt = 11)
Paragraph 11 applies
(ii)
Paragraph 11
If: alla(in_scope = true, punkt = 12)
Paragraph 12 applies
where available, information concerning any malicious actor that has exploited or that is exploiting the vulnerability;
Paragraph 12
If: alla(in_scope = true, punkt = 13)
Paragraph 13 applies
(iii)
Paragraph 13
If: alla(in_scope = true, punkt = 14)
Paragraph 14 applies
details about the security update or other corrective measures that have been made available to remedy the vulnerability.
Paragraph 14
If no rule matches: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.
The article text as read
- 11. A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. The manufacturer shall notify that actively exploited vulnerability via the single reporting platform established pursuant to Article 16.
- 22. For the purposes of the notification referred to in paragraph 1, the manufacturer shall submit:
- 3(a)
- 4an early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available;
- 5(b)
- 6unless the relevant information has already been provided, a vulnerability notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the actively exploited vulnerability, which shall provide general information, as available, about the product with digital elements concerned, the general nature of the exploit and of the vulnerability concerned as well as any corrective or mitigating measures taken, and corrective or mitigating measures that users can take, and which shall also indicate, where applicable, how sensitive the manufacturer considers the notified information to be;
- 7(c)
- 8unless the relevant information has already been provided, a final report, no later than 14 days after a corrective or mitigating measure is available, including at least the following:
- 9(i)
- 10a description of the vulnerability, including its severity and impact;
- 11(ii)
- 12where available, information concerning any malicious actor that has exploited or that is exploiting the vulnerability;
- 13(iii)
- 14details about the security update or other corrective measures that have been made available to remedy the vulnerability.
Lineage
Interface
Hashes
Artefacts
No legal advice. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.
Citation: 32024R2847 art. 14, Reporting obligations of manufacturers. ExploreWorld Legal, https://legal.exploreworldai.com/agent/cyberresiliens-2024-2847/artikel-14 (hämtad 2026-08-18, bevis sha256:91e65f9d8be73289, bygge legal-2026-08-25).