ENISA workflow

ENISA Art. 14 Reporting Workflow — X-Software GmbH

Version: 1.0
Created: 2026-07-23
Regulation: Art. 14, Regulation (EU) 2024/2847 (Cyber Resilience Act)


Trigger condition

This workflow is activated when X-Software GmbH becomes aware that a vulnerability in one of its products is being actively exploited in the wild.

⚠️ The clock starts at the moment of awareness — not at confirmation, analysis completion, or patch availability.


Step 1 — 24-hour Early Warning (Art. 14(2), first indent)

Deadline: Within 24 hours of awareness
Recipient: ENISA via the Single Reporting Platform
Platform: https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp

Required information (early warning)

  • Product name and version
  • Brief description of the vulnerability
  • Indication that exploitation is occurring
  • Preliminary severity assessment

Internal owners

  • Trigger / initial report: [Security team lead]
  • Submission: [Compliance officer / Legal]
  • Document retention: [ISMS / Legal]

Step 2 — 72-hour Detailed Notification (Art. 14(2), second indent)

Deadline: Within 72 hours of awareness
Recipient: ENISA via the Single Reporting Platform

Required information (detailed notification)

  • CVE identifier (assigned or requested)
  • Technical root cause analysis
  • CVSS score (base + environmental)
  • Affected products, versions, and configurations
  • Availability of patch, workaround, or mitigation
  • Any affected supply chain partners
  • Initial exploitation details observed

Internal owners

  • Technical analysis: [Security / Engineering]
  • CVE assignment: [PSI / Security team]
  • Submission: [Compliance officer / Legal]

Step 3 — 14-day Final Report (Art. 14(3))

Deadline: Within 14 days of awareness
Recipient: ENISA via the Single Reporting Platform

Required information (final report)

  • Confirmed CVE identifier
  • Final CVSS score
  • Patch or mitigation fully available / deployed timeline
  • Full description of exploitation activity observed
  • Measures taken to prevent recurrence
  • Coordinated disclosure details (if applicable)

Internal owners

  • Technical sign-off: [Head of Engineering]
  • Legal review: [Legal / DPO]
  • Submission: [Compliance officer]
  • Advisory publication: [PR / Security team]

Concurrent obligation — User notification (Art. 14(4))

Deadline: Without undue delay — run in parallel with the above steps
Recipients: Affected users and operators

Required actions

  • Identify all affected users and downstream operators
  • Draft user-facing notification (non-technical language)
  • Select appropriate notification channel (product update, email, advisory page)
  • Publish or send the notification
  • Document: date, channel, audience, content

Record-keeping

Retain all of the following for a minimum of 5 years:

  • Submission confirmations from ENISA (with timestamps)
  • All analysis documentation
  • User notification records
  • Internal communication trail
  • Any extensions or correspondence with ENISA or competent authorities