Skip to content

Security1 publisher2 min readPublished

ENISA's new portal starts the CRA's 24-hour reporting clock for connected products sold in the EU

The Cyber Resilience Act's reporting duties started binding manufacturers on 11 September 2026, and the first release of ENISA's portal has no API, so each report is typed into an English-language web form.

The Watch · Security desk

Illustration accompanying ENISA's new portal starts the CRA's 24-hour reporting clock for connected products sold in the EU

What happened

  • ENISA switched on the Cyber Resilience Act's Single Reporting Platform on 11 September 2026, the same day the law's reporting obligations started binding, with Article 16(1) putting the agency in charge of running it.
  • The clock starts when a manufacturer becomes aware: 24 hours for an early warning, 72 hours for a notification with an initial assessment, and 14 days from the availability of a fix or mitigation for the final report.
  • The manufacturer chooses the CSIRT that takes first receipt, and a wrong choice can invalidate the notification, which then has to be resubmitted to the correct coordinator.
  • The first release ships without an API, so notifications go through a web interface that is in English at launch, with translations of the supporting material to follow.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint With no machine interface, the 24-hour early warning depends on a registered person reachable overnight and at weekends. Product security teams cover that with a rota, not with tooling.
  • decision The coordinating CSIRT gets chosen in advance or chosen badly under incident pressure, because a rejected notification has to go in again and the deadline keeps running.
  • exposure Scope follows where the product is sold, so a vendor based outside the EU with EU distribution owes the same 24-hour early warning as one established in a Member State.
  • precedent Open-source stewards get 15 more months, so maintainers of components inside regulated products stay outside the portal while the vendors shipping those components are already inside it.

Registration comes before any filing. Access runs on an EU Login account with multi-factor authentication [10]. A manufacturer gets one Primary Assigned Representative and up to 20 Secondary ARs, and the designated CSIRT validates the association [11]. An AR whose association is still pending may file up to 20 notifications before verification becomes mandatory [12]. An AR created mid-incident can therefore file before the CSIRT has validated it.

Picking the coordinator is the manufacturer's job, and in general it is the Member State of the main EU establishment, where decisions about the products' cybersecurity are predominantly taken [8]. The receiving team then forwards the notification to CSIRTs in other Member States where the product is available [6]. ENISA gets a copy at the same moment, unless the manufacturer marks one of the exceptional circumstances in Article 16(2), in which case ENISA sees partial information until the receiving CSIRT makes the rest available [7].

Deadlines differ by what is being reported. For a severe incident the final report is due one month after the 72-hour notification [5], which puts it roughly a month and three days after the moment of awareness [21]. For an actively exploited vulnerability the 14-day final report runs from the availability of a corrective or mitigating measure [4], so a bug still without a fix leaves only the 24-hour and 72-hour obligations in play [22].

A vendor with several affected product lines coordinates across its branches and subsidiaries so that exactly one notification goes in per event [14]. ENISA says organizations can automate their internal workflows and may get API functionality in a future phase, and it did not give a date [15].

"The streamlined reporting and sharing of information on actively exploited vulnerabilities and severe incidents helps to build a more resilient Digital Single Market," said ENISA Executive Director Juhan Lepassaar [17].

Voluntary reports of vulnerabilities, cyber threats, incidents and near misses under Article 15 are planned for a later phase [18]. Open-source software stewards come under the same obligation on 11 December 2027 [19], 15 months after manufacturers [20].

What to watch

  • Whether ENISA dates the API phase, which would let vendors file from their existing case management instead of a browser.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories