|

EU Launches Single Reporting Platform to Support Cyber Resilience Act Compliance

What Is the Single Reporting Platform?

The European Union Agency for Cybersecurity (ENISA) has launched the first version of the Single Reporting Platform (SRP). This online tool helps manufacturers and open-source software stewards meet their new reporting duties under the Cyber Resilience Act (CRA). Instead of sending separate reports to many different authorities, companies can now submit one report through a single system.

Why the Cyber Resilience Act Matters

The Cyber Resilience Act is a major EU law. It sets mandatory cybersecurity rules for products with digital elements, covering their entire lifecycle. Starting from 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents. The law’s main cybersecurity requirements will take effect later, on 11 December 2027. Open-source software stewards will also need to follow these reporting rules from that same date, if they are involved in developing digital products.

ENISA’s Executive Director, Juhan Lepassaar, explained that attackers often exploit product vulnerabilities to disrupt essential services, such as healthcare, energy, and transport. He said faster, shared reporting helps build a more resilient digital market across the EU.

How CSIRTs Coordinate Reporting

When a manufacturer submits a report, it first goes to a designated CSIRT (Computer Security Incident Response Team) acting as coordinator. That CSIRT then shares the information with other relevant CSIRTs in EU countries where the affected product is also sold. At the same time, ENISA also receives the notification. This process avoids delays and helps national authorities act quickly to reduce cybersecurity risks.

Who Must Use the Platform?

From 11 September 2026, manufacturers selling digital products in the EU must report serious vulnerabilities and incidents through the SRP. Open-source software stewards will join this requirement starting 11 December 2027, based on Article 24(3) of the CRA. EU CSIRTs will use the same platform to receive and share the reports they get.

Resources for Manufacturers

ENISA has created several support materials to help users understand the process. These include an FAQ, user manuals, tutorial videos, a glossary, and factsheets available in multiple EU languages. A dedicated help desk is also available for specific questions. In addition, the European Commission offers its own guidance webpage on CRA reporting obligations, along with detailed FAQs and implementation guidance.

For a practical, step-by-step walkthrough, our Technical Director at The One Lab, Jeans KOO, has also produced a tutorial video: “EU CRA Article 14 Reporting Tutorial: How to Use the ENISA Single Reporting Platform (SRP) Steps.” This video guides manufacturers through the actual reporting process on the SRP, offering a hands-on companion to ENISA’s official documentation.

ENISA also continues to support small and medium-sized enterprises (SMEs) through its Secure by Design and Default Playbook and its SME Cyber Resilience Maturity Assessment Model, which helps smaller businesses strengthen their cybersecurity practices as CRA requirements come into force.


Key Takeaways

  • Start early: Manufacturers should register for the Single Reporting Platform now, even if their affected products haven’t yet triggered a reportable incident — early familiarity reduces reporting delays later.
  • Map your reporting timeline: Confirm which CRA obligations apply to your organization now (from 11 September 2026) versus later (from 11 December 2027, for open-source stewards and main cybersecurity requirements).
  • Assign an internal owner: Designate a specific team or person responsible for monitoring vulnerabilities and filing SRP reports, since coordination with CSIRTs requires timely and accurate submissions.
  • Use ENISA’s free resources: Review the FAQ, tutorial videos, and glossary before your first submission to avoid common reporting errors.
  • SMEs should assess readiness: Smaller companies should use ENISA’s SME Cyber Resilience Maturity Assessment Model to identify gaps before the 2027 deadline.

Source of Article

ENISA. “The CRA Single Reporting Platform Is Launched.” Press Release, 11 September 2026.
https://www.enisa.europa.eu/news/the-cra-single-reporting-platform-is-launched

Additional resource:
“EU CRA Article 14 Reporting Tutorial: How to Use the ENISA Single Reporting Platform (SRP) Steps” — Tutorial video by The One Lab’s Technical Director.
https://www.youtube.com/watch?v=GfWgJNanRME&t=43s

Other posts you may find interesting...