ENISA Updates CRA Single Reporting Platform Guidance for Mandatory Cybersecurity Notifications

European Union
Sep 11, 20265 sources
  • 01From 11 September 2026, ENISA’s CRA Single Reporting Platform is the central reporting channel for Article 14 cybersecurity notifications.
  • 02The platform is designed to streamline mandatory reporting of actively exploited vulnerabilities and severe incidents affecting covered products with digital elements.
  • 03ENISA revised the platform’s user guidance on 9 and 10 September 2026; affected manufacturers should review it.
  • 04Using the platform does not remove manufacturers’ responsibility to identify reportable events, meet deadlines, and submit accurate information.
  • 05Incident-response and vulnerability-management procedures should be aligned with the platform’s reporting requirements.

ENISA’s Cyber Resilience Act (CRA) Single Reporting Platform is operational from 11 September 2026 as the central EU channel for mandatory cybersecurity notifications involving covered products with digital elements. Manufacturers and other entities subject to Article 14 of the CRA must use it to submit qualifying reports for actively exploited vulnerabilities and severe security incidents to the relevant authorities.

The platform is intended to streamline the CRA notification process by providing one reporting route. It supports the CRA’s cybersecurity requirements for certain hardware and software products sold in the EU, but it does not change the underlying legal duties. Businesses remain responsible for identifying reportable events, determining whether a vulnerability is actively exploited or an incident is severe, meeting applicable reporting deadlines, and ensuring submissions are accurate.

ENISA updated the platform’s user guidance on 9 and 10 September 2026. Organisations that use the system should review the revised material and incorporate its information requirements into their incident-response and vulnerability-management procedures.

In practice, affected organisations should establish processes to detect potential reportable events, assess whether the Article 14 threshold is met, escalate matters internally, preserve relevant technical records, and prepare and submit notifications through the platform when required.

Sources (5)

enisa.europa.euSep 11, 2026

ENISA launches Cyber Resilience Act Single Reporting Platform

enisa.europa.euSep 11, 2026

ENISA Updates Guidance for Cyber Resilience Act Single Reporting Platform

enisa.europa.euSep 11, 2026

ENISA’s CRA Single Reporting Platform Opens for Mandatory Reporting in September 2026

enisa.europa.euSep 11, 2026

ENISA Opens Cyber Resilience Act Reporting Platform

enisa.europa.euSep 11, 2026

ENISA Activates CRA Single Reporting Platform for Exploited Vulnerabilities and Severe Incidents