On September 11, 2026, the European Union Agency for Cybersecurity (ENISA) launched the Single Reporting Platform (SRP), the common electronic tool through which manufacturers of products with digital elements must now discharge their Cyber Resilience Act (CRA) reporting duties. The same date is the point from which the CRA's Article 14 vulnerability and incident reporting obligations apply to manufacturers placing connected products on the EU market.
The launch clears the last procedural obstacle to compliance. With the platform now live, manufacturers can report once and have the relevant information routed to every competent national CSIRT, instead of building bilateral notification channels to each Member State. The CRA's main cybersecurity essential requirements do not apply until December 11, 2027, so the substantive security-by-design duties are not yet enforceable, but the reporting clock starts now.
Who must report, and from when?
From September 11, 2026, every manufacturer of a product with digital elements available on the EU market must report actively exploited vulnerabilities and severe incidents affecting the security of that product. Importers and distributors carry the same duty within their supply-chain role. The obligation runs independently of the December 2027 essential-requirements deadline: reporting starts now, even though the substantive security-by-design duties are not yet enforceable.
Open-source software stewards are brought in later. Under Article 24(3) of Regulation (EU) 2024/2847, the reporting obligations extend to stewards involved in the development of products with digital elements, but that article applies only from December 11, 2027, the same date the core cybersecurity requirements take effect.
What must be reported, and how fast?
Two categories trigger a notification: actively exploited vulnerabilities and severe incidents with an impact on the security of a product with digital elements. Manufacturers must notify the competent authority without undue delay and, where feasible, within 24 hours of becoming aware, then follow up with the updates the regulation prescribes as the situation evolves.
The SRP is the designated channel. ENISA operates and maintains it and has published an FAQ, user manuals, tutorial videos, a glossary and a multilingual factsheet alongside a dedicated help desk. The European Commission's CRA reporting guidance adds clarification in Section 9.1 of its implementation guidance and Section 5 of its FAQ.
How does the Single Reporting Platform route a report?
The platform is built on a report-once, disseminate-many model. When a manufacturer submits a notification, the CSIRT designated as coordinator receives it first and forwards the information to the CSIRTs in every Member State where the affected product is also available. ENISA is copied simultaneously. This coordinated routing cuts duplicate filings and lets national teams act on the same facts in parallel rather than serially.
EU CSIRTs use the same platform on the receiving side, so the reporting workflow, the dissemination workflow and the ENISA oversight view all sit on one system. ENISA has said it will expand the platform's functionality over the coming months based on operational use.
Where does the CRA-RED boundary leave radio and telecom equipment?
For this industry the decisive point is the boundary with the Radio Equipment Directive. Radio equipment that already meets the RED cybersecurity essential requirements, set by Commission Delegated Regulation (EU) 2022/30 under Article 3(3)(e) and (f) of Directive 2014/53/EU and applicable since August 1, 2025, is excluded from the CRA's essential cybersecurity requirements. It is not excluded from the reporting duty: manufacturers of such equipment must still report actively exploited vulnerabilities and severe incidents through the SRP from September 11, 2026.
That split makes the CRA-RED interface the critical compliance pivot for 2026. A connected radio or telecom device can be fully RED-compliant on the substance of its cybersecurity design and still fall squarely inside the CRA's notification regime, so compliance teams that treated RED cybersecurity conformity as the finish line now need a parallel vulnerability-reporting workflow. Continuous, per-jurisdiction real-time monitoring surfaces the moment a reporting platform goes live and the day an obligation attaches, so a team can stand up its workflow before the clock starts.
| Date | What applies |
|---|---|
| September 11, 2026 | CRA Article 14 reporting obligations apply to manufacturers and importers; ENISA Single Reporting Platform live |
| December 11, 2027 | CRA essential cybersecurity requirements apply; Article 24(3) reporting extends to open-source software stewards |
Subscribe to the free newsletter
The immediate checklist is narrow but time-sensitive: confirm whether your products fall inside the CRA's product-with-digital-elements definition or only under the RED cybersecurity carve-out, register on the SRP and test the submission flow, map the 24-hour internal escalation path from security or product teams to whoever files the notification, and brief engineering and legal on the split between the September 2026 reporting deadline and the December 2027 essential-requirements deadline. Obsidian tracks both milestones across the EU cybersecurity stack.


