ENISA Launches CRA Single Reporting Platform for Actively Exploited Vulnerabilities
ENISA activated the Cyber Resilience Act Single Reporting Platform on September 11, 2026, coinciding with the implementation of mandatory reporting obligations for manufacturers.
Key Features of the Platform
The platform, developed and managed by the EU Agency for Cybersecurity, fulfills requirements outlined in Article 16(1) of the CRA. Manufacturers introducing products with digital components into the EU market must now disclose actively exploited vulnerabilities and significant incidents via this centralized portal. The reporting timeline initiates when the manufacturer gains awareness of the issue.
Reporting Process
Notifications are submitted electronically and assigned to a designated CSIRT, the national incident response team responsible for initial receipt. This team forwards the report to CSIRTs in other EU member states where the product is distributed. ENISA receives a copy simultaneously unless the manufacturer invokes exceptions under Article 16(2), in which case partial data is shared until the receiving CSIRT completes the information.
Registration and Coordination
Manufacturers are required to select the coordinator CSIRT, typically the EU member state where their primary operations are based. Incorrect selection may result in invalidation of the submission, necessitating resubmission to the appropriate authority. Registration requires an EU Login account with multi-factor authentication.
Compliance and Operational Guidelines
Each manufacturer is assigned one Primary Assigned Representative and up to 20 Secondary ARs, with the designated CSIRT verifying these associations. Pending verification, an AR may submit up to 20 notifications before mandatory validation is enforced. The platform aims to enhance transparency and coordination in addressing cybersecurity threats, fostering a more resilient Digital Single Market, according to ENISA Executive Director Juhan Lepassaar.
Technical Limitations and Future Updates
The initial release lacks API integration, requiring manual submissions through the web interface. ENISA notes that organizations may automate internal processes and anticipates API functionality in future updates. Each product line requires a separate notification, regardless of scale.
Language and Expansion Plans
The platform is launched in English, with translated supporting materials planned for subsequent phases. Voluntary reporting of vulnerabilities, threats, and incidents under Article 15 is scheduled for later implementation. Open-source software maintainers will face similar obligations starting December 11, 2027.
The system streamlines information sharing, ensuring timely dissemination of critical security data across EU member states. Manufacturers must adhere to strict procedural guidelines to maintain compliance and avoid disruptions in reporting. The initiative reflects broader regulatory efforts to strengthen cybersecurity frameworks and accountability within the digital economy.
