ENISA Updates CRA Guidance on Reporting Representatives’ Notifications
Key Takeaways
- 01ENISA updated its CRA reporting guidance on September 12, 2026.
- 02The guidance covers submissions and updates made by assigned representatives through ENISA’s reporting platform.
- 03It applies to notifications concerning actively exploited vulnerabilities and severe incidents.
- 04Affected organizations should align their reporting procedures with the ENISA platform process.
The European Union Agency for Cybersecurity (ENISA) updated its Cyber Resilience Act (CRA) guidance on September 12, 2026. The guidance explains how assigned representatives must submit and update notifications through ENISA’s reporting platform for actively exploited vulnerabilities and severe incidents.
The guidance is intended to support the CRA’s incident and vulnerability reporting process. It covers notifications made by assigned representatives, rather than leaving reporting entities to rely on an informal or separate reporting route.
Companies and representatives responsible for CRA reporting should ensure they can use ENISA’s platform and have internal procedures to identify reportable actively exploited vulnerabilities and severe incidents, make notifications, and submit updates when circumstances change.