Terminus · EU Cyber Resilience Act, Article 14
The reporting clock started on September 11. Can you show when yours did?
Article 14 gives manufacturers 24 hours for an early warning, 72 hours for a notification, and 14 days after a fix for the final report, all counted from the moment you became aware. Terminus records that moment and every step after it, signed and numbered, on your own infrastructure.
Incident-evidence pilot: $7,500, fixed fee. 60 days. One product line, one deployment.
- T+00:00#0141triage-leadawareness declared: exploitation confirmed
- T+00:12#0142triage-leadaffected versions listed
- T+01:40#0877build-svcmitigation build started
- T+06:05#0143triage-leadMember States identified
- T+21:30#0311psirt-ownerearly warning submitted (24 h limit)
- T+30:00#0878build-svcmitigation build signed
- ——#0879build-svcno receipt
- T+51:15#0880build-svcfixed release published
- T+68:40#0312psirt-ownernotification submitted (72 h limit)
The hard question comes after the report
Filing on time is half of it. When an authority, a customer or your own board asks how you knew the timeline was right, a ticket history and a chat export are weak answers. Anyone with admin access could have edited them, and nothing shows what's missing.
Terminus gives each person, service and script its own numbered, signed receipts. A step that was skipped or deleted leaves a gap in the numbers. A separately written verifier checks the whole record offline, so whoever reviews it doesn't have to trust your systems or ours.
- Signed receipt
- One record per action: who acted, what they did, when, and the sequence number, signed as it happens.
- Per-actor sequence
- Every person, service and script numbers its own receipts. A missing number shows up as a gap.
- Offline verdict
- A separately written verifier re-checks signatures, order and gaps offline and returns consistent, inconsistent or indeterminate.
- Ledger segment
- The receipts for one window of time, handed over with the verifier's output so a reviewer can check them without your systems.
Article 14, line by line
Reporting applies from September 11, 2026. The rest of the Regulation applies from December 11, 2027. Forward this table to legal.
| Reference | What it asks | What Terminus records | What stays yours |
|---|---|---|---|
| Art. 14(1), 14(2)(a) | Early warning of an actively exploited vulnerability within 24 hours of becoming aware, naming the Member States where the product is available. | A receipt for the awareness decision (who, when) and a receipt for the submission. The time between them is on the ledger, not pieced together later. | Deciding awareness and submitting through the ENISA Single Reporting Platform. |
| Art. 14(2)(b) | Vulnerability notification within 72 hours: the product, the nature of the exploit, and the corrective or mitigating measures taken and available to users. | Receipts for each triage, mitigation and release step between hour 0 and hour 72. Per-actor numbering shows any step that was skipped or deleted. | The content of the notification. |
| Art. 14(2)(c) | Final report no later than 14 days after a corrective or mitigating measure is available. | A receipt for the release of the fix, which starts the 14-day window, and a receipt for the final report. | Writing and submitting the final report. |
| Art. 14(3), 14(4) | Severe incidents: early warning within 24 hours, incident notification within 72 hours, final report within one month of the notification. | The same receipt chain, tagged as an incident instead of a vulnerability, so both clocks are read from one ledger. | Classifying the incident as severe and submitting each stage. |
| Art. 14(8) | Inform impacted users of the vulnerability or incident and of the measures they can take. | A receipt for each user notice: the channel, the time, and the release it refers to. | The notice itself and choosing the channel. |
| Annex I, Part II | Vulnerability handling requirements, applying from December 11, 2027. | The handling steps above, recorded as they happen, so the 2027 evidence already exists when someone asks for it. | The vulnerability handling process and policy. |
Evidence mapping, not certification. This table shows which records Terminus produces for a reviewer to examine. Whether an obligation is met is decided by you, your auditor or the competent authority.
Start with a pilot, keep it with a license
Terminus runs on your infrastructure. We don't host your ledger, and there's no portal holding your evidence. You pay for the software, the signed updates and the people who wrote it.
Incident-evidence pilot
$7,500
Fixed fee. 60 days. One product line, one deployment.
- Terminus installed in your environment, by your team, with us on the call
- Receipts wired to your intake, triage and release steps
- One rehearsed Article 14 timeline, checked by the verifier
- The pilot fee is credited against a first-year license
Annual license
Priced per deployment. Written quote within one business day.
Twelve months. Self-hosted. Signed releases and updates.
- License file that verifies offline, with no call home
- Signed release downloads, SBOM and release notes
- Machine-readable mapping files for every framework we publish
- Email support from the people who wrote the code
Air-gapped deployment
Quoted per site.
For networks with no route out.
- Releases delivered on signed media
- License, updates and verifier all work with the network unplugged
- Installation support on site or over a controlled channel
We sell software and we audit, so we keep the two apart. An organization that licenses Terminus can't engage SSX360 to assess the systems Terminus covers. An organization we're assessing can't license Terminus during the engagement or for twelve months after our report. SSX360 never audits or badges a Terminus licensee, and Terminus never sends us your keys or your ledger.
Common questions
When do CRA Article 14 reporting duties apply?
From September 11, 2026. Manufacturers must send an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident, a notification within 72 hours, and a final report later. The rest of the Regulation applies from December 11, 2027.
Does Terminus submit reports to ENISA for me?
No. You decide awareness and submit through the ENISA Single Reporting Platform. Terminus records each step as a signed, numbered receipt so you can show the timeline afterwards.
Where does the ledger live?
On your infrastructure. SSX360 does not host your ledger or receive your keys, and the license file verifies offline.
What does the pilot cost?
$7,500, fixed fee, for 60 days covering one product line and one deployment. The fee is credited against a first-year license.
Running NIS2 or DORA reporting as well? The same ledger covers them. Ask for those mappings.
Rehearse your first Article 14 timeline before you need it.
RJ York, mission@ssx360.com, +1 617 595 9115. Hawaiʻi, HST (UTC−10). Replies within one business day.
