08 Oct 2026 On article 14 of the Cyber Resilience Act
The successful entry into force of Article 14 of the Cyber Resilience Act1 on September 11th, 2026, is jeopardized by the lack of clarity in the meaning of “actively exploited vulnerability” (AEV) and “severe incident having an impact on the security of a product with digital elements” (SI) which are to be reported by manufacturers.
These ambiguities will substantially hamper the successful implementation of Article 14 starting from September 11th. These will lead to fragmentation across Member States regarding security monitoring of the EU market, will create market distortion within the EU market as manufacturers will be subject to diverging national interpretations and ultimately will expose them to legal risks resulting from uncertainty.
Eurosmart notes that further clarification on these aspects has so far received limited attention, be in the FAQ2 or the CRA guidance3. Therefore, Eurosmart calls on the European Commission to provide clarification on the ambiguities outlined below as soon as possible.
Article-14-of-CRA-Paper

