CRA: Single Reporting Platform launched, reporting requirements apply with immediate effect
At a glance
As of 11 September 2026, the CRA reporting obligations are in force, requiring manufacturers to report actively exploited vulnerabilities and serious incidents through ENISA’s new Single Reporting Platform (CRA-SRP).
Manufacturers must assess both new and existing products and establish processes to identify, evaluate and report incidents within the CRA’s strict deadlines.
Companies should promptly identify CRA-relevant products, implement reporting procedures and familiarise responsible teams with the CRA-SRP and its requirements.
On 11 September 2026, the central reporting platform Single Reporting Platform (CRA SRP) for the EU Cyber Resilience Act (CRA) went live. Since then, the reporting obligations set out in Article 14 of the CRA have been binding. Manufacturers of products with digital elements (PDEs) have to report any actively exploited vulnerabilities and severe security incidents via the CRA SRP to ENISA and the relevant national CSIRT coordinator.
Impact on existing products
One important point which is often unclear in practice is that the reporting requirements apply not only to new products, but also to products already on the market before the CRA comes into force on 11 December 2027, provided they fall within its scope. Vulnerabilities whose active exploitation was already known prior to 11 September 2026 do not need to be reported retrospectively. However, if it is established after this cut-off date that a previously known vulnerability is being actively exploited, the reporting requirement will apply in full. This means that it is crucial to know which products are actually considered “products with digital elements” (PDEs) for the purposes of Article 3(1) of the CRA.
When must a report be submitted?
Under Article 14(1) of the CRA, a manufacturer must report any actively exploited vulnerability or any severe incident in its product as soon as it becomes aware of it. An actively exploited vulnerability is deemed to exist where there is “reliable evidence” that a malicious actor has actually exploited it without the system owner’s permission. The Commission’s guidance states that a manufacturer is to be regarded as having become aware of a vulnerability if after an initial assessment it concludes “with a reasonable degree of certainty” that a vulnerability contained in its product is being actively exploited. The CRA provides for a three-stage, tightly scheduled reporting procedure: an early warning within 24 hours, a notification within 72 hours and a final report after 14 days or one month.
The Regulation does not specify in detail when information constitutes “reliable evidence” of active exploitation. It is clear, however, that a zero-day vulnerability that has merely been discovered or reported in the course of testing is not sufficient. There must be robust evidence that an attacker has exploited the vulnerability in a live system without authorisation. Entries in CISA’s KEV, the European Vulnerability Database and the CVE lists are strong indicators, but do not replace a case-by-case assessment. When integrating third-party components, manufacturers have to independently verify whether there is indeed reliable evidence of active exploitation in their own product.
It is also worth noting that under the CRA manufacturers are not contractually obliged to require suppliers of third-party components to report security incidents. Despite this, manufacturers should still require their suppliers to do this as best practice, since the responsibility for actively exploited vulnerabilities in a product lies solely with the manufacturer. Only vulnerabilities that can actually be exploited in the specific product are subject to mandatory reporting.
Initial version with limitations
At the launch on 11 September 2026, the CRA SRP only supports mandatory reporting under Articles 14 and 24 of the CRA. Voluntary reporting under Article 15 of the CRA (e.g. of vulnerabilities not actively exploited) is only planned for a later phase of the platform’s development.
Reporting portal, FAQs and glossary
Technical implementation is managed centrally via the CRA SRP, which is operated, maintained and secured by ENISA. The actual reporting platform is provided as a separate portal with a log-in at https://portal.cra-srp.enisa.europa.eu.
ENISA recommends only initiating registration and validation when a report is actually to be submitted. ENISA provides further technical and organisational advice in its continuously updated guidance documents.
Three key ENISA resources are available to assist with preparing the contents:
- Portal: Single Reporting Platform (SRP) | ENISA
- FAQs: Frequently Asked Questions | ENISA
- Glossary: CRA SRP Glossary | ENISA
Bottom line
11 September 2026 marks one of the most critical implementation deadlines under the CRA: The reporting requirements apply immediately and across the whole of Europe. This also covers products that have already been placed on the market. Given this, manufacturers in particular should clarify as soon as possible which of their products are classified as PDEs, establish internal processes for identifying and assessing actively exploited vulnerabilities and severe incidents, and familiarise themselves with ENISA’s resources on registration and the reporting process at an early stage.
Well
informed
Subscribe to our newsletter now to stay up to date on the latest developments.
Subscribe now









