CRAArt. 14voice-validated
CRA Art14: Art. 14
CRA
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
Manufacturers must notify ENISA and the competent CSIRT designated as coordinator without undue delay and in any event within 24 hours of becoming aware of any actively-exploited vulnerability, and any severe incident having an impact on the security of the product. Subsequent reports follow at 72 hours (full incident notification) and within 14 days (final root-cause assessment).
ATT&CK techniques this article tests · 0
| Technique | Why it maps | Confidence |
|---|
Defending mitigations · 6
| Mitigation | What it does | Confidence |
|---|---|---|
| M1047 | Comprehensive auditing helps detect actively exploited vulnerabilities and severe incidents, enabling timely notification as required by CRA Art. 14. | 80% |
| M1031 | Preventing unauthorized code execution reduces the likelihood of actively exploited vulnerabilities leading to severe incidents, aligning with CRA Art. 14. | 70% |
| M1038 | Implementing exploit protection directly prevents the successful exploitation of vulnerabilities, reducing severe incidents and supporting CRA Art. 14 compliance. | 90% |
| M1030 | Segmenting networks limits the scope of severe incidents and lateral movement, reducing impact and aiding in CRA Art. 14 reporting. | 70% |
| M1028 | Hardening operating systems reduces the attack surface, preventing actively exploited vulnerabilities and severe incidents, supporting CRA Art. 14. | 80% |
| M1050 | Regular vulnerability scanning identifies weaknesses before they become actively exploited, directly addressing the spirit of CRA Art. 14. | 90% |
Underlying weaknesses · 7
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-79 | XSS vulnerabilities are actively exploited, leading to severe incidents that require reporting under CRA Art. 14. | 80% |
| CWE-89 | SQL Injection is a common actively exploited vulnerability, resulting in severe incidents requiring notification under CRA Art. 14. | 90% |
| CWE-20 | Lack of input validation is a root cause for many actively exploited vulnerabilities and severe incidents, directly relevant to CRA Art. 14. | 90% |
| CWE-287 | Weak authentication can lead to unauthorized access, a severe incident requiring notification under CRA Art. 14. | 80% |
| CWE-276 | Default insecure permissions enable privilege escalation, contributing to severe incidents and actively exploited vulnerabilities under CRA Art. 14. | 70% |
| CWE-327 | Weak cryptography can lead to data breaches, a severe incident requiring notification under CRA Art. 14. | 70% |
| CWE-502 | Deserialization vulnerabilities are actively exploited for remote code execution, leading to severe incidents under CRA Art. 14. | 80% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0170 compute · voice-rubric self-validated · 1 hallucination(s) dropped at validation