CRAArt. 14voice-validated

CRA Art14: Art. 14

CRA

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

Manufacturers must notify ENISA and the competent CSIRT designated as coordinator without undue delay and in any event within 24 hours of becoming aware of any actively-exploited vulnerability, and any severe incident having an impact on the security of the product. Subsequent reports follow at 72 hours (full incident notification) and within 14 days (final root-cause assessment).

ATT&CK techniques this article tests · 0

TechniqueWhy it mapsConfidence

Defending mitigations · 6

MitigationWhat it doesConfidence
M1047Comprehensive auditing helps detect actively exploited vulnerabilities and severe incidents, enabling timely notification as required by CRA Art. 14.
80%
M1031Preventing unauthorized code execution reduces the likelihood of actively exploited vulnerabilities leading to severe incidents, aligning with CRA Art. 14.
70%
M1038Implementing exploit protection directly prevents the successful exploitation of vulnerabilities, reducing severe incidents and supporting CRA Art. 14 compliance.
90%
M1030Segmenting networks limits the scope of severe incidents and lateral movement, reducing impact and aiding in CRA Art. 14 reporting.
70%
M1028Hardening operating systems reduces the attack surface, preventing actively exploited vulnerabilities and severe incidents, supporting CRA Art. 14.
80%
M1050Regular vulnerability scanning identifies weaknesses before they become actively exploited, directly addressing the spirit of CRA Art. 14.
90%

Underlying weaknesses · 7

CWEWhy it persistsConfidence
CWE-79XSS vulnerabilities are actively exploited, leading to severe incidents that require reporting under CRA Art. 14.
80%
CWE-89SQL Injection is a common actively exploited vulnerability, resulting in severe incidents requiring notification under CRA Art. 14.
90%
CWE-20Lack of input validation is a root cause for many actively exploited vulnerabilities and severe incidents, directly relevant to CRA Art. 14.
90%
CWE-287Weak authentication can lead to unauthorized access, a severe incident requiring notification under CRA Art. 14.
80%
CWE-276Default insecure permissions enable privilege escalation, contributing to severe incidents and actively exploited vulnerabilities under CRA Art. 14.
70%
CWE-327Weak cryptography can lead to data breaches, a severe incident requiring notification under CRA Art. 14.
70%
CWE-502Deserialization vulnerabilities are actively exploited for remote code execution, leading to severe incidents under CRA Art. 14.
80%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0170 compute · voice-rubric self-validated · 1 hallucination(s) dropped at validation