EU Cyber Resilience Act: Single Reporting Platform Goes Live
EU Cyber Resilience Act: Single Reporting Platform Goes Live
10 septembre 2026
Global
Global
Global
From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through ENISA’s Single Reporting Platform within 24 hours. Internal reporting workflows and platform access credentials should be in place now.
Why should I read this?
The EU Cyber Resilience Act (CRA) reporting regime goes live on 11 September 2026. From that date, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through the Single Reporting Platform (SRP), operated by the EU Agency for Cybersecurity (ENISA). One submission reaches the relevant national cybersecurity authorities across the EU.
The clock is short: an early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report within 14 days of a fix for vulnerabilities or within one month for incidents. Registering on the platform takes minutes and is only needed when a report is due; what takes time is the internal workflow to detect, decide and file within 24 hours. Full application of the CRA, including penalties, follows on 11 December 2027.
What should I do?
Manufacturers should act now on platform access, internal process design and reporting-scope review.
Prepare your Assigned Representatives for the SRP. Designate a primary and a backup Assigned Representative (AR), the platform role that submits notifications. Each AR needs an EU Login account with multi-factor authentication, created in advance. Register only when a notification is due; the national Computer Security Incident Response Team (CSIRT) validates the AR afterwards without blocking submission.
Map your product portfolio against the CRA’s scope. Identify every product with digital elements you make or market under your own brand in the EU, from connected sensors and industrial controllers to standalone software. The obligation covers all such products, not only those classified as important or critical.
Build a reporting workflow and templates. The 24-hour clock starts when you become aware of an actively exploited vulnerability, meaning one with reliable evidence of exploitation by a malicious actor. A firmware flaw in a connected device that attackers are using is the typical case. Security operations, product and legal teams must be able to triage and submit within that window. Pre-draft templates for the 72-hour notification (vulnerability, exploit, corrective measures) and the final report, due within 14 days of a fix for vulnerabilities or within one month for incidents.
Identify your coordinating CSIRT. The coordinator is the CSIRT of the manufacturer’s EU main establishment, where product cybersecurity decisions are predominantly taken. Manufacturers without an EU main establishment follow a fallback order: authorised representative, importer, distributor, then the Member State with most users. ENISA publishes the list of designated CSIRTs on its SRP pages.
Plan how you will inform users. After becoming aware, the manufacturer must inform impacted users, and where appropriate all users, of the vulnerability or incident and of any mitigating measures they can take. Where the manufacturer fails to do so in time, the coordinating CSIRT may inform users itself.
What else do I need to know about the CRA Single Reporting Platform?
One submission, cross-border reach
The manufacturer submits one notification through the SRP, addressed simultaneously to the CSIRT designated as coordinator and to ENISA. The coordinating CSIRT disseminates without delay to CSIRTs in Member States where the product is available. Delegated Regulation (EU) 2026/881, adopted in December 2025, permits delayed dissemination where justified on cybersecurity grounds. This includes cases where the security of the SRP itself has been compromised.
Parallel obligations under NIS2 and DORA do not go away
The CRA is product-focused; NIS2, the EU directive on cybersecurity of essential and important entities, is entity-focused. Both use a 24-hour/72-hour structure, but the obligations run in parallel. Once a corrective measure is available, ENISA adds the reported vulnerability to the European vulnerability database established under NIS2. DORA, the Digital Operational Resilience Act, applies to financial entities and their information and communication technology (ICT) third-party risk; CRA obligations do not displace DORA incident reporting. Organisations under both regimes should map the overlaps now.
What comes next: Conformity assessment, standards and penalties
Full CRA application follows on 11 December 2027, when the essential cybersecurity requirements, conformity assessment, market surveillance and penalties take effect. Fines are set by each Member State within EU ceilings of up to EUR 15 million or 2.5% of worldwide turnover, and imposed by national market surveillance authorities. Micro and small enterprises cannot be fined for missing the 24-hour deadline.
The harmonised standards that will give manufacturers a presumption of conformity are still being developed. The Commission’s guidance of 27 July 2026 explains the reporting obligations in practice and is worth reading alongside ENISA’s platform guidance. Open-source software stewards will also be subject to reporting obligations from 11 December 2027, to the extent they are involved in developing the products. Voluntary reporting through the SRP will follow in a later phase.
Further reading on the CRA Single Reporting Platform
Eversheds Sutherland prend toutes les précautions raisonnables et nécessaires pour s'assurer que les informations et les documents, y compris, mais sans s'y limiter, les articles, les bulletins d'information, les rapports, les enquêtes et les blogs ("matériel") sur le site Web d'Eversheds Sutherland sont exacts et complets. Toutefois, ces documents sont fournis à titre d'information générale uniquement, et non dans le but de fournir des conseils juridiques, et ne reflètent pas nécessairement la législation ou la réglementation en vigueur. Ces documents ne doivent pas être interprétés comme des conseils juridiques sur quelque sujet que ce soit.
Les documents peuvent ne pas refléter les développements juridiques les plus récents. Le contenu et l'interprétation des documents, ainsi que la législation qui y est abordée, peuvent faire l'objet de révisions.
Aucune déclaration ou garantie, expresse ou implicite, n'est faite quant à l'exactitude ou à l'exhaustivité de la documentation et il convient donc de ne pas s'y fier. Eversheds Sutherland décline toute responsabilité en ce qui concerne les mesures prises ou non prises sur la base de tout ou partie du contenu des documents, dans toute la mesure permise par la loi. Les documents n'ont pas vocation à être exhaustifs ou à inclure des conseils sur lesquels vous pouvez vous appuyer. Vous devez toujours consulter un juriste/avocat dûment qualifié pour toute question juridique spécifique.
Les opinions exprimées dans les documents sont celles de leur auteur et ne reflètent pas nécessairement celles d'Eversheds Sutherland ou de tout autre avocat.