CRA Final Report
The final deadline is not the same for an actively exploited vulnerability and a severe security incident.
Actively exploited vulnerability
The final report is due no later than 14 days after a corrective or mitigating measure becomes available. It includes at least a description of the vulnerability including severity and impact, available information about malicious actors exploiting it, and details of the security update or other corrective measures.
Severe incident
The final report is due within one month after submission of the 72-hour incident notification. It includes at least a detailed description of the incident and its severity and impact, the threat type or likely root cause, and applied and ongoing mitigation measures.
Keep the actual trigger date
For vulnerabilities, record when the corrective or mitigating measure became available. For severe incidents, record when the 72-hour notification was actually submitted. CRA Report uses those explicit dates to calculate the corresponding final milestone.