Agent · cyberresiliens-2024-2847-14
Cyberresiliensakten artikel 14: Reporting obligations of manufacturers
Strukturelt tre: artikkelens egne punkter, ordrett.
CELEX 32024R2847 · 2026-08-18 · Vekt 78 · minimal-risk
ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.
CyberresiliensaktenOffisiell kilde
- Hva siden er
- Agent, Cyberresiliensakten artikel 14
- Lest mot offisiell kilde
- 2026-08-18Fersk
- Ansvarlig utgiver
- ExploreWorld Legal, redaksjonenAnsvarsposisjon
Kort svar
What does Cyberresiliensakten Article 14 require, and what outcome does the rule tree give?
Cyberresiliensakten Article 14 is tested here by a deterministic rule tree of 14 rules, built from the article's own conditions. The tree reads your facts and names the outcome that applies, starting with Paragraph 1 applies, carrying paragraph citation, content hash and read date 2026-08-18 against CELEX 32024R2847. The outcome is a machine classification, not a compliance decision.
Cyberresiliensakten Article 14Lest mot utgiveren 2026-08-18Offisiell tekst
- Paragraph 1 applies. 1. A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. The manufacturer shall notify that actively exploited vulnerability via the single reporting platform established pursuant to Article 16.
- Paragraph 2 applies. 2. For the purposes of the notification referred to in paragraph 1, the manufacturer shall submit:
- Paragraph 3 applies. (a)
En kildehenvisning, ikke juridisk rådgivning.
Jurisdiksjon
Samme agent, lest med ett lands øyne.
Inndata
- in_scopeThe article applies to the situationboolean
- punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)
Regeltre
Hvis: alla(in_scope = true, punkt = 1)
Paragraph 1 applies
1. A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. The manufacturer shall notify that actively exploited vulnerability via the single reporting platform established pursuant to Article 16.
Punkt 1
Hvis: alla(in_scope = true, punkt = 2)
Paragraph 2 applies
2. For the purposes of the notification referred to in paragraph 1, the manufacturer shall submit:
Punkt 2
Hvis: alla(in_scope = true, punkt = 3)
Paragraph 3 applies
(a)
Punkt 3
Hvis: alla(in_scope = true, punkt = 4)
Paragraph 4 applies
an early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available;
Punkt 4
Hvis: alla(in_scope = true, punkt = 5)
Paragraph 5 applies
(b)
Punkt 5
Hvis: alla(in_scope = true, punkt = 6)
Paragraph 6 applies
unless the relevant information has already been provided, a vulnerability notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the actively exploited vulnerability, which shall provide general information, as available, about the product with digital elements concerned, the general nature of the exploit and of the vulnerability concerned as well as any corrective o…
Punkt 6
Hvis: alla(in_scope = true, punkt = 7)
Paragraph 7 applies
(c)
Punkt 7
Hvis: alla(in_scope = true, punkt = 8)
Paragraph 8 applies
unless the relevant information has already been provided, a final report, no later than 14 days after a corrective or mitigating measure is available, including at least the following:
Punkt 8
Hvis: alla(in_scope = true, punkt = 9)
Paragraph 9 applies
(i)
Punkt 9
Hvis: alla(in_scope = true, punkt = 10)
Paragraph 10 applies
a description of the vulnerability, including its severity and impact;
Punkt 10
Hvis: alla(in_scope = true, punkt = 11)
Paragraph 11 applies
(ii)
Punkt 11
Hvis: alla(in_scope = true, punkt = 12)
Paragraph 12 applies
where available, information concerning any malicious actor that has exploited or that is exploiting the vulnerability;
Punkt 12
Hvis: alla(in_scope = true, punkt = 13)
Paragraph 13 applies
(iii)
Punkt 13
Hvis: alla(in_scope = true, punkt = 14)
Paragraph 14 applies
details about the security update or other corrective measures that have been made available to remedy the vulnerability.
Punkt 14
Hvis ingen regel treffer: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.
Artikkelteksten som ble lest
- 11. A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. The manufacturer shall notify that actively exploited vulnerability via the single reporting platform established pursuant to Article 16.
- 22. For the purposes of the notification referred to in paragraph 1, the manufacturer shall submit:
- 3(a)
- 4an early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available;
- 5(b)
- 6unless the relevant information has already been provided, a vulnerability notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the actively exploited vulnerability, which shall provide general information, as available, about the product with digital elements concerned, the general nature of the exploit and of the vulnerability concerned as well as any corrective or mitigating measures taken, and corrective or mitigating measures that users can take, and which shall also indicate, where applicable, how sensitive the manufacturer considers the notified information to be;
- 7(c)
- 8unless the relevant information has already been provided, a final report, no later than 14 days after a corrective or mitigating measure is available, including at least the following:
- 9(i)
- 10a description of the vulnerability, including its severity and impact;
- 11(ii)
- 12where available, information concerning any malicious actor that has exploited or that is exploiting the vulnerability;
- 13(iii)
- 14details about the security update or other corrective measures that have been made available to remedy the vulnerability.
Opphav
Grensesnitt
Hasher
Artefakter
Ingen rådgivning. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.
Sitering: 32024R2847 art. 14, Reporting obligations of manufacturers. ExploreWorld Legal, https://legal.exploreworldai.com/agent/cyberresiliens-2024-2847/artikel-14 (hämtad 2026-08-18, bevis sha256:91e65f9d8be73289, bygge legal-2026-08-25).