Tec Nikan
فارسی
Talk to us
All news

ENISA Opens the CRA Single Reporting Platform

From 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents, and there is now a working channel to do it through.

Cyber Resilience ActENISAcompliancevulnerability reportingPSIRT

ENISA has deployed the initial operating capability of the Single Reporting Platform, the online tool through which manufacturers and open-source software stewards meet their Cyber Resilience Act reporting obligations. ENISA developed it and operates and maintains it.

The date is the point. From 11 September 2026, manufacturers placing products with digital elements on the EU market must report actively exploited vulnerabilities and severe incidents affecting the security of their products. A report goes to a designated CSIRT coordinator, which then disseminates it to other relevant CSIRTs in the member states where the product is available, with ENISA notified simultaneously. The main CRA cybersecurity requirements apply from 11 December 2027, as do open-source software stewards' obligations under Article 24(3).

ENISA has published FAQs, user manuals, tutorial videos, glossaries and factsheets in multiple EU languages, and runs a help desk for reporting entities. Executive director Juhan Lepassaar noted that vulnerabilities in digital products are often exploited by threat actors to subvert or hamper critical services.

For an industrial IoT or edge vendor selling in Europe, the question has moved from preparation to process. Reporting within CRA timelines requires knowing, quickly, that a vulnerability in your product is being actively exploited — which in turn requires product telemetry, a functioning PSIRT intake, and a triage path with named owners and no gaps at weekends. Most mid-sized industrial vendors have some of that and very few have all of it.

The single-platform design at least removes one burden: a single submission propagates across member state CSIRTs, rather than requiring parallel filings for a product sold EU-wide.

Want to work with us?

Tell us what you're building and we'll help you scope the first deployment.