46 days until 11 September 2026

The 24-hour clock, handled

From 11 September 2026, an actively exploited vulnerability in a product you sell in the EU means telling ENISA within 24 hours. Most people freeze because they think the early warning needs a full write-up. It does not.

What the 24-hour early warning actually needs

At 24 hours you need five things: the notification type, the level, your name, the product and a title. The CVE ID is optional. There is no CVSS field at any stage. That is the whole early warning.

  • Notification type (Vulnerability / Incident)
  • Notification level (24h / 72h / Final)
  • Name of manufacturer or open-source software steward
  • Product
  • Title

Is this even reportable?

A decision tree that walks the actual test. Article 14 covers actively exploited vulnerabilities and severe incidents, not every CVE in your SBOM. Getting a firm no, with the reasoning recorded, is as useful as getting a yes.

Three countdowns, stated in full

Opening a case starts the clocks: 24 hours for the early warning, 72 hours for the full notification, and the final report 14 days after a corrective measure for a vulnerability or one month for a severe incident. Deadlines are shown as absolute times, not "in 14 hours".

Drafted against the real field set

Twelve common fields, fourteen vulnerability fields, thirteen incident fields, each carrying its per-stage obligation level so you can see what is required now and what can wait. The field set is versioned (currently 2026-07-17), so a change at ENISA is a data update rather than a rebuild.

Rehearsal mode

Run a complete fake incident and produce all three drafts before anything is real. Templates cannot be written while a 24-hour clock is running, which is the whole point. Rehearsal artifacts are labelled so clearly that none of them can be mistaken for a filing.

An audit log you cannot edit

Every action on a case is appended to a hash-chained log. The database refuses updates and deletes on it. You can export the chain and anyone can verify it.

We do not pretend to file for you

ENISA has confirmed no APIs at this stage. Submission is manual entry into a web portal reached through EU Login. Any vendor claiming system-to-system filing is describing something that does not exist. What we do is prepare and validate the notification and lay it out in submission order, so manual entry takes minutes.

See the pricesWhat happens on 11 September