The EU Agency for Cybersecurity (ENISA) has deployed the initial operating capability of the Single Reporting Platform (SRP).
The Agency has developed, operates and maintains the online tool to enable manufacturers and open-source software stewards to meet their new Cyber Resilience Act (CRA) reporting obligations for actively exploited vulnerabilities and severe incidents. Designed to support effective vulnerability management across the EU, the SRP allows users to report once and communicate the relevant information to all appropriate authorities.
Developing the first stage of the platform marks an important milestone in the implementation of the CRA and supports a more coordinated EU approach to the reporting and handling of cybersecurity risks affecting products with digital elements available on the EU market. This is why the CRA is also critical for the protection of end-users and the safeguarding of our shared connected ecosystem from cyber threats.
ENISA’s Executive Director Juhan Lepassaar said: “Vulnerabilities in digital products are often exploited by threat actors to subvert or hamper critical services, such as healthcare, energy, transport or telecommunications. The streamlined reporting and sharing of information on actively exploited vulnerabilities and severe incidents helps to build a more resilient Digital Single Market.”
What is the Cyber Resilience Act’s Single Reporting Platform?
The CRA is the EU’s horizontal regulatory framework that introduces mandatory cybersecurity requirements for products with digital elements throughout their lifecycle. The CRA’s reporting obligations apply to manufacturers from 11 September 2026, while its main cybersecurity requirements obligations apply from 11 December 2027. ENISA was mandated to develop and operate the Single Reporting Platformas the common electronic reporting mechanism supporting these new obligations. The SRP enables manufacturers and open-source stewards to fulfil their CRA reporting obligations through a single platform, while ENISA will continue to improve and expand its functionalities over the coming months based on operational experience and user needs.
ENISA would like to thank all stakeholders who contributed to the development, scanning and testing of the platform, including national CSIRTs, the CRA Expert Group, selected manufacturers and other users whose feedback helped strengthen its functionality, security and usability.
What are the benefits of the SRP?
Manufacturers and open-source software stewards can now report through a single platform. Once a notification is submitted, the Computer Security Incident Response Team (CSIRT) designated as a coordinator that initially receives it, disseminates the information to other relevant CSIRTs in Member States where the affected product is also available, while the notification is simultaneously made available to ENISA. This coordinated approach helps relevant CSIRTs receive the information they need more efficiently and supports faster action to mitigate cybersecurity risks and strengthen resilience.
The CRA and the SRP support a more coordinated approach to vulnerability and incident reporting across the EU and a better understanding of the cyber threat landscape and emerging trends. The SRP also enables national CSIRTs and other relevant authorities to coordinate and act on the information received and mitigate risks stemming from these vulnerabilities.
The platform was developed to be functional and user-friendly while meeting all security requirements.
Who is the platform for?
From today, 11 September 2026, manufacturers are required to report actively exploited vulnerabilities and severe incidents having an impact on the security of products with digital elements. In accordance with Article 24(3) of the CRA, these reporting obligations will also apply to open-source software stewards to the extent that they are involved in the development of products with digital elements. This article shall apply from 11 December 2027.
The platform will be used by EU CSIRTs to receive and disseminate the relevant notifications.
What are the available resources for guidance?
SRP ENISA Guidance
The platform incorporates security measures to protect the confidentiality of the information submitted. ENISA has developed a range of supporting materials to help manufacturers and open-source software stewards including an FAQ, user manuals, tutorial videos, the SRP glossary and a dedicated factsheet in different EU languages. ENISA will continue to update and expand this supporting material as necessary.
A dedicated help desk is also available for questions related to reporting not addressed in the published guidance materials.
European Commission SRP Guidance
For broader guidance on the CRA reporting obligations, the European Commission provides additional resources including its dedicated Cyber Resilience Act - Reporting obligations webpage, and further clarifications on reporting obligations in Section 9.1 of the Commission guidance on the application of the CRA, as well as in Section 5 of its Frequently Asked Questions on the CRA implementation.
Cyber Resilience Guidance
ENISA also works to strengthen cybersecurity by promoting secure by design and secure by default principles in the EU market. Among its key initiatives are the publication of the Secure by Design and Default Playbook and regular Technical Advisories on product security.
The Agency also prepared SMEs for implementation of the CRA and has created an SME Cyber Resilience Maturity Assessment Model with simple and practical guidance for SMEs to identify improvements and strengthen their cyber resilience practices. A survey on CRA investments in SMEs will be launched soon.