Skip to content

Terminus · EU Cyber Resilience Act, Article 14

The reporting clock started on September 11. Can you show when yours did?

Article 14 gives manufacturers 24 hours for an early warning, 72 hours for a notification, and 14 days after a fix for the final report, all counted from the moment you became aware. Terminus records that moment and every step after it, signed and numbered, on your own infrastructure.

Incident-evidence pilot: $7,500, fixed fee. 60 days. One product line, one deployment.

terminus ledger, incident 2026-114time / seq / actor / action
  1. T+00:00#0141triage-leadawareness declared: exploitation confirmed
  2. T+00:12#0142triage-leadaffected versions listed
  3. T+01:40#0877build-svcmitigation build started
  4. T+06:05#0143triage-leadMember States identified
  5. T+21:30#0311psirt-ownerearly warning submitted (24 h limit)
  6. T+30:00#0878build-svcmitigation build signed
  7. ——#0879build-svcno receipt
  8. T+51:15#0880build-svcfixed release published
  9. T+68:40#0312psirt-ownernotification submitted (72 h limit)
verifier: build-svc gap at #0879. Timeline not marked consistent.
A rehearsal, for illustration. Both deadlines were met and the verifier still caught a build step with no record. Better to find that in a rehearsal than in front of a market surveillance authority.

The hard question comes after the report

Filing on time is half of it. When an authority, a customer or your own board asks how you knew the timeline was right, a ticket history and a chat export are weak answers. Anyone with admin access could have edited them, and nothing shows what's missing.

Terminus gives each person, service and script its own numbered, signed receipts. A step that was skipped or deleted leaves a gap in the numbers. A separately written verifier checks the whole record offline, so whoever reviews it doesn't have to trust your systems or ours.

Signed receipt
One record per action: who acted, what they did, when, and the sequence number, signed as it happens.
Per-actor sequence
Every person, service and script numbers its own receipts. A missing number shows up as a gap.
Offline verdict
A separately written verifier re-checks signatures, order and gaps offline and returns consistent, inconsistent or indeterminate.
Ledger segment
The receipts for one window of time, handed over with the verifier's output so a reviewer can check them without your systems.

Article 14, line by line

Reporting applies from September 11, 2026. The rest of the Regulation applies from December 11, 2027. Forward this table to legal.

EU Cyber Resilience Act Article 14 obligations and the Terminus evidence for each
ReferenceWhat it asksWhat Terminus recordsWhat stays yours
Art. 14(1), 14(2)(a)Early warning of an actively exploited vulnerability within 24 hours of becoming aware, naming the Member States where the product is available.A receipt for the awareness decision (who, when) and a receipt for the submission. The time between them is on the ledger, not pieced together later.Deciding awareness and submitting through the ENISA Single Reporting Platform.
Art. 14(2)(b)Vulnerability notification within 72 hours: the product, the nature of the exploit, and the corrective or mitigating measures taken and available to users.Receipts for each triage, mitigation and release step between hour 0 and hour 72. Per-actor numbering shows any step that was skipped or deleted.The content of the notification.
Art. 14(2)(c)Final report no later than 14 days after a corrective or mitigating measure is available.A receipt for the release of the fix, which starts the 14-day window, and a receipt for the final report.Writing and submitting the final report.
Art. 14(3), 14(4)Severe incidents: early warning within 24 hours, incident notification within 72 hours, final report within one month of the notification.The same receipt chain, tagged as an incident instead of a vulnerability, so both clocks are read from one ledger.Classifying the incident as severe and submitting each stage.
Art. 14(8)Inform impacted users of the vulnerability or incident and of the measures they can take.A receipt for each user notice: the channel, the time, and the release it refers to.The notice itself and choosing the channel.
Annex I, Part IIVulnerability handling requirements, applying from December 11, 2027.The handling steps above, recorded as they happen, so the 2027 evidence already exists when someone asks for it.The vulnerability handling process and policy.

Evidence mapping, not certification. This table shows which records Terminus produces for a reviewer to examine. Whether an obligation is met is decided by you, your auditor or the competent authority.

Start with a pilot, keep it with a license

Terminus runs on your infrastructure. We don't host your ledger, and there's no portal holding your evidence. You pay for the software, the signed updates and the people who wrote it.

Incident-evidence pilot

$7,500

Fixed fee. 60 days. One product line, one deployment.

  • Terminus installed in your environment, by your team, with us on the call
  • Receipts wired to your intake, triage and release steps
  • One rehearsed Article 14 timeline, checked by the verifier
  • The pilot fee is credited against a first-year license

Annual license

Priced per deployment. Written quote within one business day.

Twelve months. Self-hosted. Signed releases and updates.

  • License file that verifies offline, with no call home
  • Signed release downloads, SBOM and release notes
  • Machine-readable mapping files for every framework we publish
  • Email support from the people who wrote the code

Air-gapped deployment

Quoted per site.

For networks with no route out.

  • Releases delivered on signed media
  • License, updates and verifier all work with the network unplugged
  • Installation support on site or over a controlled channel

We sell software and we audit, so we keep the two apart. An organization that licenses Terminus can't engage SSX360 to assess the systems Terminus covers. An organization we're assessing can't license Terminus during the engagement or for twelve months after our report. SSX360 never audits or badges a Terminus licensee, and Terminus never sends us your keys or your ledger.

Common questions

When do CRA Article 14 reporting duties apply?

From September 11, 2026. Manufacturers must send an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident, a notification within 72 hours, and a final report later. The rest of the Regulation applies from December 11, 2027.

Does Terminus submit reports to ENISA for me?

No. You decide awareness and submit through the ENISA Single Reporting Platform. Terminus records each step as a signed, numbered receipt so you can show the timeline afterwards.

Where does the ledger live?

On your infrastructure. SSX360 does not host your ledger or receive your keys, and the license file verifies offline.

What does the pilot cost?

$7,500, fixed fee, for 60 days covering one product line and one deployment. The fee is credited against a first-year license.

Running NIS2 or DORA reporting as well? The same ledger covers them. Ask for those mappings.

Rehearse your first Article 14 timeline before you need it.

RJ York, mission@ssx360.com, +1 617 595 9115. Hawaiʻi, HST (UTC−10). Replies within one business day.