cra

Art. 14(3)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (6)

Techniques referencing this article

  • IMP-0001Deception (or Misdirection)ST0009
    triggers obligation
    moderate
    direct

    Deception that affects the authenticity or integrity of important data or functions meets the Art. 14(5)(a) severe-incident threshold and triggers the 14(3) notification obligation to the CSIRT-coordinator and ENISA.

  • IMP-0002DisruptionST0009
    triggers obligation
    moderate
    direct

    Disruption that negatively affects the availability of important functions meets the 14(5)(a) severe-incident threshold and triggers manufacturer notification obligations under 14(3).

  • IMP-0003DenialST0009
    triggers obligation
    moderate
    direct

    Denial that eliminates the availability of important functions meets the 14(5)(a) severe-incident threshold; the manufacturer must notify CSIRT-coordinator and ENISA per 14(3).

  • IMP-0004DegradationST0009
    triggers obligation
    moderate
    direct

    Permanent degradation of an essential function meets the 14(5)(a) severe-incident threshold for availability impact and triggers 14(3) notification obligations.

  • IMP-0005DestructionST0009
    triggers obligation
    high
    direct

    Destruction of data or functions is a clear severe-incident case under Art. 14(5)(a) — it eliminates availability and may also affect integrity — triggering the manufacturer's 14(3) notification obligations.

  • IMP-0006TheftST0009
    triggers obligation
    moderate
    direct

    Theft of mission-critical data affects confidentiality of important data — meeting the 14(5)(a) severe-incident threshold and triggering the manufacturer's 14(3) notification obligations.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.