ENISA Art. 14 Reporting Workflow — X-Software GmbH
Version: 1.0
Created: 2026-07-23
Regulation: Art. 14, Regulation (EU) 2024/2847 (Cyber Resilience Act)
Trigger condition
This workflow is activated when X-Software GmbH becomes aware that a vulnerability in one of its products is being actively exploited in the wild.
⚠️ The clock starts at the moment of awareness — not at confirmation, analysis completion, or patch availability.
Step 1 — 24-hour Early Warning (Art. 14(2), first indent)
Deadline: Within 24 hours of awareness
Recipient: ENISA via the Single Reporting Platform
Platform: https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp
Internal owners
- Trigger / initial report: [Security team lead]
- Submission: [Compliance officer / Legal]
- Document retention: [ISMS / Legal]
Step 2 — 72-hour Detailed Notification (Art. 14(2), second indent)
Deadline: Within 72 hours of awareness
Recipient: ENISA via the Single Reporting Platform
Internal owners
- Technical analysis: [Security / Engineering]
- CVE assignment: [PSI / Security team]
- Submission: [Compliance officer / Legal]
Step 3 — 14-day Final Report (Art. 14(3))
Deadline: Within 14 days of awareness
Recipient: ENISA via the Single Reporting Platform
Internal owners
- Technical sign-off: [Head of Engineering]
- Legal review: [Legal / DPO]
- Submission: [Compliance officer]
- Advisory publication: [PR / Security team]
Concurrent obligation — User notification (Art. 14(4))
Deadline: Without undue delay — run in parallel with the above steps
Recipients: Affected users and operators
Required actions
Record-keeping
Retain all of the following for a minimum of 5 years:
- Submission confirmations from ENISA (with timestamps)
- All analysis documentation
- User notification records
- Internal communication trail
- Any extensions or correspondence with ENISA or competent authorities