Independent information resource Product security · EU CRA
CRA reporting / 08

How the CRA Single Reporting Platform Works

Understand how the Cyber Resilience Act Single Reporting Platform works, including ENISA's role, CSIRT selection, notification routing, reporting stages and manufacturer responsibilities.

IN BRIEF

The SRP is the operational reporting route for Article 14. Manufacturers remain responsible for selecting the correct coordinating CSIRT, submitting the required reporting stages and keeping the notification updated. ENISA manages the platform, while coordinating CSIRTs receive and handle notifications and disseminate relevant information through the CRA reporting framework.

01 / 09

The SRP Is the CRA's Central Reporting Route

Article 16 provides for a single reporting platform in order to simplify the reporting obligations created by the CRA. ENISA established the platform and manages and maintains its day-to-day operation. The platform became operational on 11 September 2026, the same date on which Article 14 reporting became applicable. Manufacturers use the SRP for mandatory notifications concerning actively exploited vulnerabilities and severe incidents having an impact on product security. The central model is intended to avoid requiring manufacturers to make separate notifications to multiple national authorities for the same qualifying event.

  • The SRP is established under Article 16.
  • ENISA manages and maintains the platform.
  • The SRP became operational on 11 September 2026.
  • Current mandatory Article 14 reporting is submitted through the SRP.
  • The platform supports a report-once model.
02 / 09

The Manufacturer Selects the Relevant Coordinating CSIRT

Submitting through one EU platform does not remove the need to identify the correct national CSIRT designated as coordinator. The manufacturer is responsible for determining the relevant CSIRT according to Article 14(7) and selecting it in the SRP. In general, the analysis begins with the Member State of the manufacturer's main establishment in the Union, meaning the place where decisions related to the cybersecurity of its products with digital elements are predominantly taken. Article 14 contains further routing rules when that location cannot be determined or where the manufacturer has no main establishment in the Union. Selecting the correct CSIRT is therefore a legal routing decision, not simply a platform preference.

  • Determine the relevant CSIRT before submission where possible.
  • Apply the Article 14(7) routing rules.
  • Select the relevant CSIRT in the SRP.
  • Document the reasoning used for cross-border or non-EU manufacturers.
03 / 09

One Notification Is Used for a Qualifying Event

ENISA's current guidance states that only one notification is required for a given actively exploited vulnerability or severe incident even where a manufacturer has multiple branches or subsidiaries in the EU or a parent company outside the EU. The manufacturer remains responsible for coordinating internally across its corporate structure so that the required notification is submitted. This makes central product-security governance important for groups with several EU entities. Duplicate reporting by different subsidiaries can create confusion, while assuming another entity has reported can result in no submission at all. Internal ownership should therefore be agreed before a qualifying event occurs.

  • Coordinate Article 14 reporting across the corporate group.
  • Avoid duplicate submissions for the same qualifying event.
  • Assign central reporting ownership.
  • Do not assume another subsidiary has submitted without confirmation.
04 / 09

Submitted Notifications Enter a Wider Regulatory Network

Under the normal reporting flow, a notification submitted through the SRP is made available to the selected CSIRT designated as coordinator and to ENISA. The CSIRT initially receiving the notification is responsible for disseminating relevant information through the platform to other relevant CSIRTs in Member States where the product is also available. Relevant information can also reach market surveillance authorities as provided by the CRA framework. The manufacturer therefore submits through one platform, while the regulatory system manages onward distribution. Particularly exceptional circumstances can affect the dissemination process under Article 16, but they do not turn the SRP into a private manufacturer-only incident database.

  • The manufacturer submits through the SRP.
  • The coordinating CSIRT receives the notification.
  • ENISA normally receives the notification through the platform.
  • The coordinating CSIRT handles onward dissemination to relevant CSIRTs.
  • Relevant market surveillance authorities can receive information through the framework.
05 / 09

Reporting Continues Through Multiple Stages

The SRP supports the Article 14 reporting sequence rather than a single static incident form. The manufacturer begins with the 24-hour early warning and then continues to the 72-hour notification and the applicable final report. Information requirements change as the reporting stage advances. ENISA's SRP Glossary provides field-level guidance and identifies which fields apply to the early-warning, 72-hour and final-report stages, as well as whether fields are required, optional or required when information is available. Reporting teams should therefore treat a notification as an ongoing regulatory case until all applicable stages are completed.

  • Stage 1: 24-hour early warning.
  • Stage 2: 72-hour notification.
  • Stage 3: applicable final report.
  • Update information as the investigation and remediation develop.
  • Use current ENISA field guidance for the reporting stage.
06 / 09

Assigned Representatives Operate the Manufacturer Account

ENISA uses Assigned Representatives, or ARs, for manufacturer interaction with the SRP. Current ENISA guidance distinguishes a Primary AR from Secondary ARs. The Primary AR has additional administrative permissions connected to the manufacturer association, while both Primary and Secondary ARs can submit and update notifications according to their access permissions. Associated representatives use personal EU Login accounts with multi-factor authentication. This operating model means the reporting process should not depend on a single person's availability. Manufacturers should plan representation, account access and internal authority so a qualifying event can be reported even when the normal primary contact is unavailable.

  • Assigned Representatives use personal EU Login accounts.
  • Multi-factor authentication is required.
  • The Primary AR manages additional manufacturer-association functions.
  • Secondary ARs can provide operational reporting resilience.
  • Avoid designing the reporting process around one unavailable individual.
07 / 09

Notification Ownership Can Continue Across Reporting Stages

ENISA's current platform guidance allows Primary and Secondary ARs associated with the same manufacturer to access, view and update notifications for that manufacturer according to their permissions. This supports continuity when different team members need to manage different reporting stages. Drafts are an important exception because ENISA states that draft notifications are stored locally in the individual AR's account and are not visible to other ARs associated with the manufacturer. Teams should therefore avoid relying on an unfinished private draft as the only record of an approaching deadline. The underlying evidence and reporting status should also be maintained in the manufacturer's controlled internal case record.

  • Use manufacturer-associated ARs for reporting continuity.
  • Do not rely on one person's local draft.
  • Maintain the regulatory case in the manufacturer's internal system.
  • Track who is responsible for each Article 14 stage.
08 / 09

The Platform Does Not Replace Manufacturer Responsibility

The SRP simplifies the reporting route, but it does not make the reporting decision for the manufacturer. The manufacturer remains responsible for determining whether an actively exploited vulnerability or severe incident meets the Article 14 trigger, establishing when it became aware, meeting the deadlines, selecting the relevant coordinating CSIRT and providing the required information. The platform also does not replace the manufacturer's technical vulnerability-handling, incident-response, remediation or user-communication processes. A compliant operating model therefore connects internal product-security systems to the SRP workflow while keeping the underlying decision evidence under manufacturer control.

  • The manufacturer determines whether Article 14 is triggered.
  • The manufacturer records the awareness time.
  • The manufacturer selects the relevant coordinating CSIRT.
  • The manufacturer completes each required reporting stage.
  • The manufacturer remains responsible for remediation and user communication.
09 / 09

Prepare the SRP Process Before the 24-Hour Clock Starts

Reporting readiness should be established before the next security event. The organisation should know its likely Article 14 routing, identify reporting owners, maintain EU Login access for relevant representatives, document how the coordinating CSIRT will be selected and create an internal case template covering the 24-hour, 72-hour and final-report stages. Product and version information, vulnerability evidence, incident evidence, mitigation status and user-communication status should be available to the reporting team without lengthy manual searches. The objective is not to pre-complete a regulatory notification, but to remove avoidable administrative delays from an already short reporting timeline.

  • Identify reporting owners.
  • Maintain working EU Login and MFA access.
  • Understand the coordinating-CSIRT routing rules.
  • Prepare an Article 14 internal case template.
  • Connect product-security evidence to the reporting workflow.
  • Exercise the process using a realistic scenario.
REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.