Reporting obligations begin: an actively exploited vulnerability in your product must be reported to ENISA within 24 hours of becoming aware of it.
Twenty-four hours is not a process you can invent on the day. You need to know who decides it is reportable, who files it, and where the evidence lives, before the clock starts.
Source: Regulation (EU) 2024/2847, Article 14 →