Deadlines
The 24-hour early warning: what ENISA’s form asks for, field by field
Published . Reviewed against Regulation (EU) 2024/2847, OJ L, 20.11.2024, Commission guidance C(2026) 5252 and the ENISA CRA SRP Glossary, version 1.4. Position as at 9 October 2026.
The first filing under Article 14 is the early warning. It is due within 24 hours of awareness, and you make it in a form with fixed fields and fixed limits. This post reads that form against the Regulation. It shows which fields are required, how long each may be, and what to prepare before the clock starts.
Which version of the form this post uses
ENISA publishes the field list of its single reporting platform as the CRA SRP Glossary. This post uses version 1.4. ENISA dated that version 1 October 2026, and Cybiq read it on 9 October 2026. ENISA changes the glossary, so the post names the version it used, and Cybiq watches the page for changes. The glossary is a platform specification, not law. Check the live form before you rely on a single field.
What the Regulation asks for in the first 24 hours
Each track has its own early warning. The text of the vulnerability early warning is short.
“an early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it”
“indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available”
The incident early warning adds one required statement.
“an early warning notification of a severe incident having an impact on the security of the product with digital elements, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it”
“including at least whether the incident is suspected of being caused by unlawful or malicious acts, which shall also indicate, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available”
When the 24 hours start
Both clocks run from awareness. Commission guidance, which is non-binding, says that a manufacturer becomes aware, and the reporting clocks start, when after an immediate initial assessment of a suspicious event it has a reasonable degree of certainty that a vulnerability in its product is being actively exploited or that a severe incident has compromised the product's security (guidance paragraph 213). It adds that when a manufacturer counts as aware depends on the case: sometimes it is clear at once, sometimes it takes time to establish that the product is affected and exploited. The emphasis is on a prompt initial assessment, above all where the vulnerability may pose a significant risk, followed by remediation and notification (guidance paragraph 214). The guidance is not binding, so keep a record of how you reached your view of the moment you became aware.
The required fields, counted from the glossary
Glossary version 1.4 marks eight fields as required at the vulnerability early warning and nine at the incident early warning. Both tracks share the first seven.
Required on both tracks
| No. | Field | Limit | Expected format |
|---|---|---|---|
| 1 | Notification type (Vulnerability/Incident) | none stated | Select one: Vulnerability or Incident |
| 2 | Title | 255 characters | Plain text; concise title |
| 3 | Summary | 4000 characters | Short paragraph |
| 4 | Manufacturer name | none stated | System-generated / read-only |
| 5 | Member States where product available (Concerned CSIRT) | none stated | Select one or more Member States |
| 6 | Product Name | 255 characters | Official product name |
| 7 | Product Version | 255 characters | Version or version range |
Field 4 is filled by the system and is read-only. You type the title, the summary, the product name and the product version, and you choose the notification type and the Member States.
Also required on the vulnerability track
| No. | Field | Limit | Expected format |
|---|---|---|---|
| v26 | Date and time when you become aware of the Actively Exploited Vulnerability | none stated | Date and time |
Also required on the incident track
| No. | Field | Limit | Expected format |
|---|---|---|---|
| i31 | Incident is suspected of unlawful or malicious acts | 255 characters | Select one: Yes, No, Unknown |
| i37 | Date and time when you become aware of the incident (UTC time) | none stated | Date and time |
The vulnerability early warning therefore has eight required fields and the incident early warning has nine.
Two footnotes in the glossary
The vulnerability awareness field is not on the platform yet. ENISA marks field v26, the date and time you became aware of the actively exploited vulnerability, as required. Its footnote says the field will be available in the next release of the platform. Today seven of the eight required fields can be filled, and one arrives with the next platform release. Until then, record the awareness time in your own log and state it in the summary.
The incident awareness field is labelled “detected”. In the current release, field i37 is named as the date and time the incident was detected. Article 14(4)(a) runs from awareness, not detection. Enter the awareness time, and say in the summary that you did.
The optional fields at the early warning
Every other field is optional at this stage: twelve on both tracks, nine more on the vulnerability track and seven more on the incident track. Optional on this form does not mean unimportant. The glossary marks several of them as required at the 72-hour notification or at the final report, so the early warning is the cheapest moment to start collecting them.
Optional on both tracks
| No. | Field | Limit |
|---|---|---|
| 8 | Product Type (Default/Important Product with Digital Elements/Critical Product with Digital Elements) | none stated |
| 9 | Product class | none stated |
| 10 | Product category | none stated |
| 11 | End of support indicator | none stated |
| 12 | Component name | 255 characters |
| 13 | Mitigating measure expected shortly | none stated |
| 14 | User Action able to reduce impact | 4000 characters |
| 15 | Considered sensitivity of information | 255 characters |
| 16 | Corrective or mitigating measures taken | 2000 characters |
| 17 | Corrective or mitigating measures that users can take | 4000 characters |
| 40 | AR Note | none stated |
| 41 | CSIRT Note | none stated |
Optional on the vulnerability track
| No. | Field | Limit |
|---|---|---|
| v19 | CVE ID | 255 characters |
| v20 | EUVD ID | 255 characters |
| v21 | General information | 4000 characters |
| v22 | Date when corrective or mitigating measure has been available | none stated |
| v23 | Details about the security update/corrective measure available | 2000 characters |
| v24 | Full description of the Severity of the vulnerability | 4000 characters |
| v25 | Full description of the Impact of the vulnerability | 4000 characters |
| v27 | Malicious actor that has exploited/is exploiting the vulnerability | 100 characters |
| v30 | Please provide further information | 800 characters |
Optional on the incident track
| No. | Field | Limit |
|---|---|---|
| i32 | General information, about the nature of the incident | 4000 characters |
| i33 | Applied and ongoing mitigation measures | 4000 characters |
| i34 | Detailed description of the Severity of the incident | 4000 characters |
| i35 | Detailed description of the Impact of the incident | 4000 characters |
| i36 | Type of Threat or root cause that is likely to have triggered incident | 255 characters |
| i38 | Date and time when the incident occurred (UTC time) | none stated |
| i39 | Initial assessment of the incident | 4000 characters |
Where the form and the Regulation differ
The two texts do not line up in either direction.
The form asks for more than the Regulation names. The text of the 24-hour early warning names the Member States and, for incidents, the suspicion of unlawful or malicious acts. The form also requires a title of up to 255 characters, a summary of up to 4000 characters, a product name and a product version. Those are the platform’s own requirements. You meet them because the platform will not accept the filing without them.
The Regulation names more than the form requires. Article 14(2)(b) sets out what the 72-hour vulnerability notification shall provide.
“which shall provide general information, as available, about the product with digital elements concerned, the general nature of the exploit and of the vulnerability concerned as well as any corrective or mitigating measures taken, and corrective or mitigating measures that users can take, and which shall also indicate, where applicable, how sensitive the manufacturer considers the notified information to be”
In glossary version 1.4, fields 15, 16 and 17 carry that content: the sensitivity of the information, the measures taken and the measures users can take. The glossary marks all three optional at the notification stage. Optional on the form is not optional in the Regulation. Follow the Regulation for what to say and the form for where to put it.
What to prepare before an incident
- An awareness log. Record when the suspicious event was first seen, when the initial assessment started and when you reached a reasonable degree of certainty. Add who decided. The log gives you the time to enter in the awareness field.
- A draft outside the platform. The form has limits: 255 characters for the title, the product name and the product version, and 4000 for the summary. Write the text in a document where you can count characters, then paste it in. The 24 hours then go on content, not on trimming.
- The product facts. Keep the official product name, the version string or range, and the list of Member States where the product is available in one place that anyone on call can find.
Two ways to use this
The free Is this vulnerability or incident reportable? Article 14 check puts the Article 14 questions to a single event. It runs in your browser and keeps nothing.
The €199 pack includes the awareness-timestamp log and the Article 14 notification templates. The templates print the glossary version 1.4 field list and limits next to the Regulation’s content, dated and watched. Cybiq never files or transmits anything on your behalf.
Orientation, not legal advice. Verify against the official text before relying on any item.