Independent information resource Product security · EU CRA
CRA reporting / 14

What Happens if the CRA Reporting Platform Is Unavailable?

Understand what manufacturers should do if the CRA Single Reporting Platform is temporarily unavailable, including direct CSIRT communication and the requirement to submit through the SRP after service is restored.

IN BRIEF

Temporary SRP unavailability changes the operational route available at that moment, but it does not eliminate the CRA reporting obligation. Manufacturers should preserve evidence of the outage, consider urgent direct communication with the designated CSIRT where necessary, and complete the formal SRP submission after restoration.

01 / 08

Check Whether the SRP Is Actually Unavailable

A failed login or individual browser problem is not necessarily a platform-wide outage. ENISA maintains a CRA Single Reporting Platform Status page indicating whether the platform is available or temporarily unavailable. Reporting teams should check the official status information and rule out local authentication, EU Login, MFA, browser or connectivity problems where possible. The internal Article 14 case should record when access was attempted and what official platform status was observed.

  • Check the official ENISA SRP Status page.
  • Distinguish platform unavailability from a local access problem.
  • Record attempted access times.
  • Preserve relevant screenshots or status evidence internally.
02 / 08

ENISA Says to Submit When the Platform Is Restored

ENISA's current FAQ states that where the SRP is temporarily unavailable, manufacturers should wait until the platform becomes available again and then submit the required notification through the SRP. The outage therefore does not convert Article 14 reporting into a permanently different reporting channel. The regulatory case should remain open and ready for submission so the Assigned Representative can complete the required platform step promptly after service returns.

  • Keep the notification information ready.
  • Monitor restoration of the SRP.
  • Submit through the SRP after restoration.
  • Do not treat temporary unavailability as cancellation of the reporting obligation.
03 / 08

Urgent Direct Communication With the CSIRT Is Possible

ENISA also recognises that a manufacturer may consider immediate communication necessary before the SRP is restored. In that situation, the manufacturer may contact its designated CSIRT directly. The manufacturer should use the correct CSIRT determined under Article 14(7) and should preserve a record of what was communicated, when it was sent and who received it. This contingency can help ensure urgent security information reaches the relevant authority during an outage.

  • Determine the correct designated CSIRT.
  • Use direct communication where immediate communication is considered necessary.
  • Record the communication time and content.
  • Keep the Article 14 SRP submission prepared.
04 / 08

Direct CSIRT Contact Does Not Replace the SRP Submission

This distinction is central to ENISA's current guidance. Even where the manufacturer has directly contacted the designated CSIRT during an outage, the required notification must still be submitted through the Single Reporting Platform once it becomes available again. Internal procedures should therefore describe direct CSIRT communication as an interim contingency step rather than an alternative final reporting route.

  • Direct CSIRT contact is not the final SRP submission.
  • Submit again through the SRP when service is restored.
  • Reference the earlier communication in the internal case record.
  • Avoid closing the regulatory task after sending an email or making another direct contact.
05 / 08

Keep the Original Article 14 Timeline in the Case Record

A platform outage should not cause the organisation to lose the underlying Article 14 timing information. The case record should still identify when the manufacturer became aware of the actively exploited vulnerability or severe incident, when the 24-hour and 72-hour limits would ordinarily fall and when access to the SRP was attempted. If the platform remains unavailable across a reporting milestone, this evidence can show the sequence of events and the manufacturer's actions during the outage.

  • Preserve the awareness timestamp.
  • Preserve the calculated Article 14 deadlines.
  • Record SRP access attempts.
  • Record direct CSIRT communication where used.
  • Record the eventual SRP submission time.
06 / 08

Platform Unavailability Is Different From PEC

Temporary platform unavailability should not be confused with Particularly Exceptional Circumstances. PEC is a specific Article 16 mechanism used in the 72-hour notification of an actively exploited vulnerability when one of the statutory security conditions applies. An SRP outage is an operational availability problem. ENISA's current outage guidance focuses on waiting for restoration, using direct CSIRT communication if immediate communication is necessary, and completing the SRP submission afterwards.

  • PEC concerns dissemination of sensitive AEV information.
  • Platform unavailability concerns access to the reporting system.
  • Do not select PEC merely because the SRP is unavailable.
  • Use the correct contingency process for the actual problem.
07 / 08

The Delegated Regulation Also Addresses Platform Availability at the CSIRT Level

Commission Delegated Regulation (EU) 2026/881 supplements the CRA rules on delaying dissemination by the CSIRT designated as coordinator. Among the specified circumstances is a situation in which the Single Reporting Platform has been compromised or is temporarily not operational. That rule concerns the CSIRT's ability to disseminate a notification to other relevant CSIRTs and should not be confused with the manufacturer's separate operational question of how to make its initial submission during an outage. ENISA FAQ 25 provides the current manufacturer-facing contingency guidance.

  • Delegated Regulation 2026/881 addresses delayed dissemination by the receiving CSIRT.
  • Platform compromise or temporary non-operation can affect dissemination.
  • Manufacturer submission guidance remains governed by the current ENISA SRP instructions.
  • Keep submission and authority-to-authority dissemination concepts separate.
08 / 08

Create a Platform-Outage Runbook

A short outage runbook can prevent confusion during an active reporting deadline. It should identify the ENISA SRP Status page, the manufacturer's correct coordinating CSIRT, internal reporting owners, evidence to preserve, the method for urgent direct communication and the requirement to complete the SRP submission after restoration. The runbook should also state that the Article 14 case remains open until the formal platform submission and any later reporting stages are completed.

  • Identify the SRP status source.
  • Record the coordinating CSIRT contact path.
  • Preserve outage evidence.
  • Prepare direct communication if urgently necessary.
  • Submit through the SRP after restoration.
  • Keep the regulatory case open through later reporting stages.
REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.