cra

Art. 14(9)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (7)

Techniques referencing this article

  • IMP-0001Deception (or Misdirection)ST0009
    relates to
    moderate
    direct

    Deception-impact severe incidents (primary mapping: Art. 14(3)) include scenarios where investigation continuity may justify delayed dissemination; (14)(9) provides the legal-grounds framework.

  • IMP-0002DisruptionST0009
    relates to
    moderate
    direct

    Disruption severe incidents (primary mapping: Art. 14(3)) may involve ongoing exploitation where premature notification could escalate impact; (14)(9)'s delay-grounds delegated acts are the governing instrument.

  • IMP-0003DenialST0009
    relates to
    moderate
    direct

    Denial severe incidents (primary mapping: Art. 14(3)) may justify delayed notification while attacker activity is still active on other potentially-affected products; (14)(9) governs.

  • IMP-0004DegradationST0009
    relates to
    moderate
    direct

    Degradation severe incidents (primary mapping: Art. 14(3)) may warrant delayed dissemination during ongoing forensic analysis of root cause; (14)(9) is the applicable delegated-acts framework.

  • IMP-0005DestructionST0009
    relates to
    moderate
    direct

    Destruction severe incidents (primary mapping: Art. 14(3)) may involve sensitive attribution information whose immediate release could compromise investigation; (14)(9)'s delay-grounds framework applies.

  • IMP-0006TheftST0009
    relates to
    moderate
    direct

    Theft severe incidents (primary mapping: Art. 14(3)) may justify delayed dissemination to avoid further compromise of stolen-data scope or to coordinate with law enforcement; (14)(9) governs.

  • REC-0008.03Known VulnerabilitiesST0001
    relates to
    moderate
    direct

    Known-vulnerability reconnaissance (primary mapping: Art. 14(1)) is a scenario where premature dissemination of notification could weaponize a still-unpatched vulnerability; (14)(9)'s delegated-acts on cybersecurity-grounds for delaying dissemination directly govern this case.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.