On September 11, 2026, Latvia's national computer security incident response team, CERT.LV, confirmed that the reporting obligations under Article 14 of the EU Cyber Resilience Act (Regulation (EU) 2024/2847) now apply to manufacturers of products with digital elements. From that date, any producer placing connected radio, telecom, or electrical equipment on the EU market from Latvia must notify actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform (SRP), with CERT.LV as the national CSIRT that processes those reports.

The September 11, 2026 milestone is the same day ENISA launched the SRP, and it starts the reporting clock even though the CRA's substantive cybersecurity essential requirements do not apply until December 11, 2027. CERT.LV, operated under Latvia's Ministry of Defence, told manufacturers to use the SRP as the primary channel and gave a national fallback: if a technical failure blocks an SRP submission, send the report to [email protected], then register it on the SRP once the platform is available again.

Who must report from Latvia, and what triggers a notification?

The duty falls on every manufacturer of a product with digital elements made available on the EU market, including connected routers, switches, modems, and IoT devices. Latvia-established makers such as MikroTik, the Riga-based networking equipment manufacturer, sit directly inside the scope. Importers and distributors carry the same duty within their supply-chain role. Two event categories trigger a notification: actively exploited vulnerabilities affecting the security of a product, and severe incidents with an impact on that security.

Reporting runs independently of the December 2027 deadline for the CRA's essential security-by-design requirements. A manufacturer must file from September 11, 2026 even though the substantive design duties are not yet enforceable. Radio equipment that already meets the Radio Equipment Directive cybersecurity requirements set by Commission Delegated Regulation (EU) 2022/30, applicable since August 1, 2025, is excluded from the CRA's essential requirements but not from the Article 14 reporting duty.

How does a Latvian manufacturer submit a report?

The SRP at portal.cra-srp.enisa.europa.eu is the designated channel. A Latvian manufacturer submits a notification once, and the SRP routes it to the coordinating CSIRT, which for Latvia is CERT.LV, and copies ENISA. CERT.LV then processes the report on the national side. ENISA has published legal guidance, submission guidelines, an FAQ, and a multilingual factsheet alongside the platform.

The [email protected] fallback addresses a practical gap. The SRP is new, and a submitter may hit a technical fault before a deadline. In that case the report goes to CERT.LV by email, but the manufacturer must still register the same report on the SRP after the technical problem is resolved. The fallback is not a substitute for the SRP, it is a contingency that preserves the statutory submission while the platform is unreachable. The National Cyber Security Centre (NKDC) published the companion national notice.

What are the Article 14 reporting deadlines?

Reporting moves in stages, and the first deadline is tight. An early notification is due without undue delay and no later than 24 hours after the manufacturer becomes aware of the vulnerability or incident. A more detailed message follows within 72 hours. The final report depends on the event type.

Report stageDeadlineApplies to
Early notificationWithin 24 hours of awarenessVulnerabilities and incidents
Detailed messageWithin 72 hoursVulnerabilities and incidents
Final report, incidentsWithin 1 month of first notificationSevere security incidents
Final report, vulnerabilitiesWithin 14 days of a corrective measureActively exploited vulnerabilities

Which Latvian authority does what under the CRA?

CERT.LV, the cyber incident prevention institution run under the Ministry of Defence, is the Latvian CSIRT that receives and processes Article 14 reports submitted through the SRP. For market surveillance, Latvia has not yet formally designated its CRA market-surveillance authority, and the Consumer Rights Protection Centre (CRPC, known in Latvian as PTAC) acts as the de-facto lead for electrical equipment pending that formal designation.

The full CRA security obligations, including the Annex I essential requirements, Annex II user information duties, and conformity assessment, apply from December 11, 2027. Until then, the live obligation is reporting. Latvian manufacturers need a working 24-hour escalation path from their security or product teams to whoever files the SRP notification today, not when a vulnerability surfaces.

Subscribe to the free newsletter

Latvia: radio and telecom equipment conformity under RED, EMC and the Cyber Resilience ActLive
Monitor the Latvian national application of the Union's CE-marking framework for radio, telecom and electrical equipment, for the radio, telecom and electrical-equipment compliance industry, jurisdiction Latvia.
Email report 2 news
You will receive an email report each time something new happens on this topic. Free, no account required.
Subscribe to the newsletter

The immediate checklist is narrow but time-sensitive: confirm whether your products fall inside the CRA's product-with-digital-elements definition, register on the SRP and test the [email protected] fallback path, map the 24-hour internal escalation route from security or product teams to whoever files the notification, and brief engineering and legal on the split between the September 2026 reporting deadline and the December 2027 essential-requirements deadline. Obsidian's continuous, per-jurisdiction monitoring surfaces a change like this the moment CERT.LV publishes it, so your team acts before the 24-hour clock starts.