Article 14 readiness
What counts as an actively exploited vulnerability under the CRA?
The 24-hour clock is tied to a vulnerability being used in an attack, not merely one that exists. The gap is usually a written, agreed trigger and a named person who confirms exploitation from your own signals, so the clock starts on evidence rather than on a hunch or a vendor headline.
Source: Regulation (EU) 2024/2847, Article 14. Operational readiness guidance about Regulation (EU) 2024/2847 — not legal advice or certification.
What VulnBrief does with this
The paid pack asks for the related facts, shows them back on an attestation screen, and then generates operational artifacts only from what you confirmed. Missing owners or evidence sources stay in the gap register.
Related intake fields: severity_model, vulnerability_sources, triage_owner.
Build the product-specific version
Get the runbook, notification drafts, evidence register, vulnerability-intake policy, and tabletop drill for one product. Flat $3,999, one time. Not legal advice, not certification.
Start the attested intake →