ENISA sits at the Union-level technical and coordination layer of CRA implementation. Manufacturers interact with ENISA most visibly through the Single Reporting Platform, while national CSIRTs designated as coordinators and market-surveillance authorities retain distinct statutory roles. Understanding that division prevents companies from treating ENISA, the CSIRT and the national regulator as interchangeable bodies.
ENISA Establishes and Operates the Single Reporting Platform
Article 16 requires the CRA Single Reporting Platform to be established by ENISA and states that its day-to-day operations are managed and maintained by ENISA. The platform supports mandatory notifications for actively exploited vulnerabilities and severe incidents, and ENISA is responsible for appropriate technical, operational and organisational measures to manage risks to the platform and submitted information.
- Establish the SRP.
- Manage and maintain day-to-day operations.
- Protect platform security.
- Support Union-level reporting infrastructure.
ENISA and the CSIRT Coordinator Have Different Jobs
Manufacturers use the SRP, but the CSIRT designated as coordinator plays a central role in receiving and disseminating notifications under the CRA framework. ENISA operates the platform and receives information through the system, while the coordinator is selected according to the CRA jurisdiction rules and performs the national coordination functions assigned by the Regulation. Companies should preserve this distinction in incident-response procedures.
- Identify the correct CSIRT coordinator.
- Use the ENISA-operated SRP.
- Do not treat ENISA as the manufacturer's national coordinator.
- Keep regulatory contacts role-specific.
ENISA Produces Technical Trend Reporting From CRA Notifications
Article 17 requires ENISA, based on notifications received under the CRA reporting framework, to prepare a technical report every 24 months on emerging cybersecurity-risk trends in products with digital elements and submit it to the NIS2 Cooperation Group. Relevant information is also included in ENISA's wider reporting on the state of cybersecurity in the Union.
- Analyse notification trends.
- Prepare periodic technical reports.
- Support Union-level risk understanding.
- Use aggregated lessons without confusing them with company-specific guidance.
ENISA Can Add Corrected Vulnerabilities to the European Vulnerability Database
Article 17 provides that after a security update or other corrective or mitigating measure is available, ENISA shall, in agreement with the manufacturer concerned, add a publicly known vulnerability notified under the CRA to the European vulnerability database. This connects CRA reporting with broader vulnerability information while recognising the timing of remediation and public disclosure.
- Corrective or mitigating measure available.
- Vulnerability publicly known.
- Agreement with the manufacturer.
- European vulnerability database entry.
Market Surveillance Authorities Can Request ENISA Technical Advice
The CRA allows market-surveillance authorities to request technical advice from ENISA on implementation and enforcement matters and to request analysis supporting product-compliance evaluations. ENISA can therefore support enforcement technically without becoming the ordinary authority that takes the national market-surveillance decision.
- Technical advice.
- Product-compliance analysis.
- Support for investigations.
- No replacement of national enforcement authority.
ENISA Is Also a Living Guidance Source
ENISA publishes and updates operational material for the CRA Single Reporting Platform, including FAQs, reporting guidance and terminology. These materials can be important for day-to-day reporting readiness because the platform and operational process can evolve. Companies should version-control ENISA guidance used in their procedures and review it when ENISA publishes updates.
- Monitor SRP FAQs.
- Monitor reporting instructions.
- Track glossary updates.
- Update incident procedures when operational guidance changes.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.