
EU CRA Article 14 reporting starts 11 September 2026
From 11 September 2026, EU Cyber Resilience Act Article 14 requires open source stewards and product makers to report actively exploited flaws within 24 hours.
From 11 September 2026, the first reporting duties under the European Cyber Resilience Act (CRA) take effect for makers of software and connected products, including open source maintainers who are treated as open source stewards. Patchstack CEO Oliver Sild outlined the new Article 14 obligations in a post published on 11 September 2026, explaining that the rules apply not only to commercial product manufacturers but also to open source projects without commercial intent. The law requires reporting of two situations: vulnerabilities that attackers are actively exploiting and severe security incidents affecting products. Reports must go to national cybersecurity authorities and the EU cybersecurity agency ENISA through a single EU platform.
The distinction between a manufacturer and an open source steward matters because it determines possible penalties. Patchstack uses a WordPress plugin as an example. A plugin whose code is GPL-licensed and open source but which has a premium version or another revenue model makes its seller a manufacturer, not an open source steward. A completely free and open source WordPress plugin with no commercial intent, maintained by employees of a legal entity, would be considered an open source steward instead. Article 14 obligations apply to both groups, but open source stewards cannot be fined; the EU can still use other means to remove a non-compliant product from the European market. This applies across all open source software ecosystems, not just WordPress, and the rule covers all products and software even if they were made available on the European market before 11 September 2026.
Two separate cases must be reported: actively exploited vulnerabilities and severe security incidents. Each report consists of three forms with separate deadlines. An early warning must be submitted without undue delay and within 24 hours of becoming aware. A fuller notification is due without undue delay and within 72 hours, with general information and an initial assessment. For actively exploited vulnerabilities, a final report is due no later than 14 days after a corrective measure such as a patch becomes available. For severe incidents, the final report is due within one month after the 72-hour notification. Manufacturers must also tell affected users what happened and how to protect themselves.
Reporting must go through the EU Single Reporting Platform, often called the SRP. Maintainers first need to create a personal EU Login account, which requires multi-factor authentication (MFA). The SRP does not have an API, and the platform requires three different forms to be completed manually for each report. Because the first deadline is only 24 hours, Patchstack advises creating EU accounts immediately so maintainers can meet the deadline when an actively exploited vulnerability or severe incident occurs.
To help open source maintainers handle these duties, Patchstack has launched a free-to-access platform for managed CRA Article 14 reporting. The service includes three main capabilities. Patchstack tracks the active exploitation of individual vulnerabilities, collects evidence, and notifies the maintainer when Article 14 requirements kick in. Patchstack can act as the official Assigned Representative, or AR, for the maintainer, fulfilling the reporting requirements and ensuring deadlines for each form are met. The platform also provides a single-channel managed vulnerability disclosure program (mVDP) and a bug bounty program for one or multiple software products. Patchstack says its mVDP platform was built for this purpose in collaboration with the European Union's European Innovation Council (EIC), and the company is GDPR-compliant and certified to ISO 27001 and SOC 2 Type 2. More than 1000 open source products and projects already use the Patchstack mVDP for vulnerability coordination. The company states it has coordinated more than 50 percent of all known vulnerabilities in the WordPress ecosystem and is one of the most active CVE Numbering Authorities (CNAs). Patchstack also states that its partnerships with leading web hosting companies and its RapidMitigate technology put it in a position to offer fast and detailed known exploited vulnerability (KEV) detection. The company notes it may introduce a fee in the future to cover Article 14 reporting on a per-report basis if volume becomes too high and the Single Reporting Platform does not introduce an API.
For website owners and businesses, the new EU rules are a reminder that the software they depend on, including WordPress plugins, is part of a formal reporting system when attackers exploit it. If a maintainer receives an early warning about an actively exploited vulnerability, users should expect prompt disclosure and fixes from responsible projects. AEU Hosting, a managed WordPress hosting service, can help website owners handle routine WordPress security maintenance and updates, which is a practical complement to these new reporting duties; readers should check the AEU Hosting page for the exact scope of that service.
How to Protect Yourself
- Turn on automatic updates for your website software and its add-ons (plugins) so known security holes get patched quickly.
- Subscribe to security announcements from the makers of any software you use, especially WordPress plugins, so you learn about actively exploited flaws right away.
- Before installing a new plugin or theme, check that it is actively maintained and has a clear way to report security problems.
- Use a reputable managed hosting provider that applies security patches for you, so you do not have to track every update yourself.
- Make regular backups of your website so you can restore it if an exploited vulnerability causes damage.
Terms Explained
- Cyber Resilience Act (CRA) A European Union law that sets security and reporting rules for software and connected products.
- Article 14 The part of the CRA that says makers and open source maintainers must report actively exploited flaws and serious incidents.
- open source steward A person or organisation that maintains free open source software without a commercial intent.
- actively exploited vulnerability A software security flaw that attackers are already using to break into systems.
- EU Single Reporting Platform (SRP) The official EU website where cyber incident and vulnerability reports must be filed.
- Assigned Representative (AR) A company or person officially appointed to handle reporting duties on behalf of a software maker.
- known exploited vulnerability (KEV) A security flaw that is confirmed to have been used by attackers.
- CVE Numbering Authority (CNA) An organisation that is allowed to assign official CVE identifiers to security flaws in software.