Skip to content

Product1 publisher2 min readPublished

One CRA report now reaches every member state where the product is available

ENISA's Single Reporting Platform went live on 11 September 2026, the day manufacturers' Article 14 duty applied. The coordinating CSIRT is set by where a company is established, and open-source stewards have until December 2027.

The Product Desk · Product desk

Illustration accompanying One CRA report now reaches every member state where the product is available

What happened

  • ENISA has deployed the initial operating capability of the Cyber Resilience Act's Single Reporting Platform, which became operational on 11 September 2026, the day Article 14 reporting obligations applied.
  • Manufacturers and open-source software stewards use the platform to report actively exploited vulnerabilities and severe incidents once, instead of notifying multiple national authorities individually.
  • A submitted notification is made available to ENISA at the same time, and the receiving CSIRT passes it to CSIRTs in other member states where the product is available and to market surveillance authorities as needed.
  • Reporting obligations for open-source software stewards under Article 24(3) do not apply until 11 December 2027, in accordance with Article 71(2) of the regulation.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision Group structure now decides jurisdiction. Because the coordinating CSIRT follows from the manufacturer's main location of establishment, the choice belongs to whoever maintains the corporate entities, and it has to be settled before anything is exploited.
  • exposure A notification filed to warn defenders can reach the market surveillance authority responsible for enforcement, because coordinating CSIRTs may share some information with those authorities so they can meet their obligations.
  • constraint A team that wants to flag something not yet exploited has no route through the platform until voluntary Article 15 reporting arrives in a later phase.
  • precedent For the next fifteen months the report on an exploited open-source component is the commercial vendor's to file, so downstream teams cannot wait for an upstream steward notification that is not yet due.

Somebody has to hold the login. ENISA's FAQ, updated 12 September 2026, covers the platform's purpose, reporting process, registration and use [15][20], and the routing question inside it is answered by corporate structure: the submitter selects a CSIRT designated as coordinator, and in general that is the national CSIRT determined by the manufacturer's main location of establishment under Article 14(7) [5]. A group with a Dutch sales entity and engineering in Poland has to decide which one is the manufacturer of record. Then it has to make sure named people hold working credentials for that account. That is work for legal and for whoever runs access reviews, and it is due before the first report.

The trigger is narrower than a bug queue. ENISA describes an actively exploited vulnerability as one for which there is reliable evidence that it has been exploited by a malicious actor [13], and a severe incident as one having a severe impact on a product's security, for example compromising its availability, authenticity, integrity or confidentiality [14]. Where the line falls in a specific case is not a platform question; the page points readers to the European Commission's FAQs on CRA implementation for interpretation and implementation guidance [16].

Article 16(1), quoted on the page, says that for notifications under Articles 14 and 15 "a single reporting platform shall be established by ENISA", and that the architecture "shall allow Member States and ENISA to put in place their own electronic notification end-points" [8][9]. Live today is the Article 14 mandatory half. Voluntary reporting under Article 15 is named in the legal basis and deferred to a future phase of the platform [10][18]. The one timing lever already written down is a Commission Delegated Regulation from December 2025, which sets the conditions under which dissemination of a notification may be delayed [12].

For open-source stewards the same clock starts later. From 11 September 2026 to 11 December 2027 is fifteen months [17]. In that window an exploited vulnerability in an open-source component shipped inside a commercial product is the manufacturer's to notify under Article 14, while the steward upstream has nothing due through the platform [19].

So: four fields, one row per product line you place on the EU market. The legal entity that is the manufacturer. Its main establishment. The coordinating CSIRT that follows from it. The two or three named people who can file on a Sunday. Any cell still empty is one you will be filling in when you already have reliable evidence of exploitation in hand.

What to watch

  • Whether the future phase of the platform adds Article 15 voluntary reporting, and on what timetable ENISA sets for it.
  • Whether CSIRTs use the December 2025 Delegated Regulation to delay dissemination of a real notification.
  • The first market surveillance action that can be traced back to a report filed through the Single Reporting Platform.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories