EU Cyber Resilience Act: Single Reporting Platform Goes Live
EU Cyber Resilience Act: Single Reporting Platform Goes Live
2026. gada 10. septembris
Globāli
Globāli
Globāli
From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through ENISA’s Single Reporting Platform within 24 hours. Internal reporting workflows and platform access credentials should be in place now.
Why should I read this?
The EU Cyber Resilience Act (CRA) reporting regime goes live on 11 September 2026. From that date, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through the Single Reporting Platform (SRP), operated by the EU Agency for Cybersecurity (ENISA). One submission reaches the relevant national cybersecurity authorities across the EU.
The clock is short: an early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report within 14 days of a fix for vulnerabilities or within one month for incidents. Registering on the platform takes minutes and is only needed when a report is due; what takes time is the internal workflow to detect, decide and file within 24 hours. Full application of the CRA, including penalties, follows on 11 December 2027.
What should I do?
Manufacturers should act now on platform access, internal process design and reporting-scope review.
Prepare your Assigned Representatives for the SRP. Designate a primary and a backup Assigned Representative (AR), the platform role that submits notifications. Each AR needs an EU Login account with multi-factor authentication, created in advance. Register only when a notification is due; the national Computer Security Incident Response Team (CSIRT) validates the AR afterwards without blocking submission.
Map your product portfolio against the CRA’s scope. Identify every product with digital elements you make or market under your own brand in the EU, from connected sensors and industrial controllers to standalone software. The obligation covers all such products, not only those classified as important or critical.
Build a reporting workflow and templates. The 24-hour clock starts when you become aware of an actively exploited vulnerability, meaning one with reliable evidence of exploitation by a malicious actor. A firmware flaw in a connected device that attackers are using is the typical case. Security operations, product and legal teams must be able to triage and submit within that window. Pre-draft templates for the 72-hour notification (vulnerability, exploit, corrective measures) and the final report, due within 14 days of a fix for vulnerabilities or within one month for incidents.
Identify your coordinating CSIRT. The coordinator is the CSIRT of the manufacturer’s EU main establishment, where product cybersecurity decisions are predominantly taken. Manufacturers without an EU main establishment follow a fallback order: authorised representative, importer, distributor, then the Member State with most users. ENISA publishes the list of designated CSIRTs on its SRP pages.
Plan how you will inform users. After becoming aware, the manufacturer must inform impacted users, and where appropriate all users, of the vulnerability or incident and of any mitigating measures they can take. Where the manufacturer fails to do so in time, the coordinating CSIRT may inform users itself.
What else do I need to know about the CRA Single Reporting Platform?
One submission, cross-border reach
The manufacturer submits one notification through the SRP, addressed simultaneously to the CSIRT designated as coordinator and to ENISA. The coordinating CSIRT disseminates without delay to CSIRTs in Member States where the product is available. Delegated Regulation (EU) 2026/881, adopted in December 2025, permits delayed dissemination where justified on cybersecurity grounds. This includes cases where the security of the SRP itself has been compromised.
Parallel obligations under NIS2 and DORA do not go away
The CRA is product-focused; NIS2, the EU directive on cybersecurity of essential and important entities, is entity-focused. Both use a 24-hour/72-hour structure, but the obligations run in parallel. Once a corrective measure is available, ENISA adds the reported vulnerability to the European vulnerability database established under NIS2. DORA, the Digital Operational Resilience Act, applies to financial entities and their information and communication technology (ICT) third-party risk; CRA obligations do not displace DORA incident reporting. Organisations under both regimes should map the overlaps now.
What comes next: Conformity assessment, standards and penalties
Full CRA application follows on 11 December 2027, when the essential cybersecurity requirements, conformity assessment, market surveillance and penalties take effect. Fines are set by each Member State within EU ceilings of up to EUR 15 million or 2.5% of worldwide turnover, and imposed by national market surveillance authorities. Micro and small enterprises cannot be fined for missing the 24-hour deadline.
The harmonised standards that will give manufacturers a presumption of conformity are still being developed. The Commission’s guidance of 27 July 2026 explains the reporting obligations in practice and is worth reading alongside ENISA’s platform guidance. Open-source software stewards will also be subject to reporting obligations from 11 December 2027, to the extent they are involved in developing the products. Voluntary reporting through the SRP will follow in a later phase.
Further reading on the CRA Single Reporting Platform
Eversheds Sutherland dara visu iespējamo, lai nodrošinātu, ka Eversheds Sutherland tīmekļa vietnē pieejamie materiāli, informācija un dokumenti, tostarp, bet ne tikai raksti, biļeteni, ziņojumi un emuāri ("Materiāli"), ir precīzi un pilnīgi. Tomēr Materiāli tiek sniegti tikai vispārīgas informācijas nolūkā, nevis juridisku konsultāciju sniegšanas nolūkā, un tie ne vienmēr atspoguļo spēkā esošos tiesību aktus vai noteikumus. Materiāli nav uzskatāmi par juridisku konsultāciju jebkurā jautājumā.
Materiāli var neatspoguļot jaunākās tiesību aktu norises. Materiālu saturs un interpretācija, kā arī tajos aplūkotie tiesību akti var tikt pārskatīti.
Nav sniegts skaidrs vai netiešs apliecinājums vai garantija par Materiālu precizitāti vai pilnīgumu, un tādēļ uz Materiāliem nevajadzētu paļauties. Eversheds Sutherland atsakās no jebkādas atbildības attiecībā uz darbībām, kas veiktas vai neveiktas, pamatojoties uz jebkuru vai visu Materiālu saturu, ciktāl to pieļauj likums. Materiāli nav paredzēti kā visaptveroši vai tādi, kas ietvertu padomus, uz kuriem jūs varētu paļauties. Jums vienmēr jākonsultējas ar atbilstoši kvalificētu juristu/advokātu par jebkuru konkrētu juridisku jautājumu.
Jebkurš Materiālos paustais viedoklis ir konkrētā autora viedoklis, un tas var neatspoguļot Eversheds Sutherland vai jebkura cita jurista/advokāta viedokli.