Reporting duties: the legal decision
The operational run-through is in 24 h / 72 h / 14 d procedure and the legal framework in Reporting to ENISA. This page covers three legal questions: when, who, and how to prove it.
When does the clock start?
The 24-hour period runs from the moment the manufacturer becomes aware of the actively exploited vulnerability or the severe incident.
“Becoming aware” is neither the first tool alert nor the conclusion of a full forensic analysis. It is the moment the organisation holds sufficiently serious elements to characterise the facts. In practice an internal rule is needed:
Your rule. The clock starts at the moment a credible indication of active exploitation reaches a person holding a security function — PSIRT, on-call, second-line support — whether that indication is internal or external. The timestamp of that receipt is recorded and governs.
Setting a rule more restrictive than necessary is risky: an authority will assess awareness against what the organisation ought to have known given the information it held.
How to qualify active exploitation
The criterion is reliable evidence that a malicious actor has exploited the vulnerability in a system without the permission of its owner.
| Element | Sufficient on its own? |
|---|---|
| Publication of a proof-of-concept exploit | No |
| High severity score | No |
| Listing in a public catalogue of exploited vulnerabilities | Strong indicator, to be matched against whether you carry the component |
| Consistent indicators of compromise in a customer’s logs | Yes |
| Forensic analysis establishing exploitation | Yes |
| A credible, circumstantial report from a CERT or a customer | Yes, subject to quick verification |
Technical qualification belongs to the PSIRT; the decision to report belongs to Legal. The PSIRT must pass its qualification on within a short window — you set two hours — to leave Legal time to decide.
Who decides
Three roles, to be named and backed up:
| Role | Function | Deputy |
|---|---|---|
| Qualifier | Establishes the technical facts | Head of PSIRT |
| Decider | Decides whether to report | General counsel, or a holder of a written delegation |
| Submitter | Drafts and sends via the platform | PSIRT, with the decider’s approval |
The written delegation is essential: a 24-hour deadline does not accommodate an approval chain reaching executive management over a weekend.
The default decision rule
Where serious doubt persists after qualification: report.
The reasoning is asymmetric. The Regulation expressly provides for voluntary reporting, which imposes no additional obligation. The cost of a report that was not strictly required is therefore nil in law. The cost of a missed report falls under the highest penalty ceiling.
This rule must be written down and known to the on-call team; otherwise the default decision will, in practice, be inaction.
Documenting the decision
This is the central defensive record. Every qualified event produces a register entry, whether or not you reported:
| Field | Content |
|---|---|
| Timestamp of awareness | Date, time, channel, person who received it |
| Facts | Description of the triggering element |
| Products and versions affected | List, with estimated installed base |
| Qualification | Active exploitation: yes / no / undetermined, with the elements relied on |
| Decision | Report / do not report / report voluntarily |
| Reasoning | The argument, not just the conclusion |
| Decider | Name and function |
| Timestamp of the decision | Time elapsed since awareness |
| Submissions | Early warning, notification, final report: dates and acknowledgements |
| User notification | Date, channel, content |
A register containing only reported events is suspect: it implies no negative decision was ever taken, which is implausible.
Legal on-call cover
A 24-hour deadline spans nights, weekends and public holidays. That requires:
- a legal on-call rota, or failing that a standing delegation to an available function;
- pre-filled templates carrying your company identifiers, so drafting is not the bottleneck;
- live named access to the reporting platform for on-call staff, tested and unexpired;
- an escalation procedure if the decider cannot be reached, with a maximum delay before switching to the deputy.
The three regimes in parallel
One event may fall under the CRA, NIS 2 and the GDPR. The comparison table is in Interplay with other legislation. The crisis cell must rule on all three simultaneously, with three distinct templates — handling them in sequence mechanically overruns the shortest deadline.