Manufacturers Report CRA Incidents to ENISA Ahead of the CSIRT
5 min read
On 11 September 2026, the reporting obligation under the Cyber Resilience Act takes effect for manufacturers of products with digital elements. The EU agency ENISA is providing the Single Reporting Platform for this purpose. Assignment to the national computer security incident response team (CSIRT) may run in parallel and does not pause the 24-hour deadline.
Key Takeaways
- The first stage applies on 11 September 2026. Manufacturers must report actively exploited vulnerabilities and serious incidents affecting the product.
- ENISA operates the reporting channel. ENISA has scheduled the launch of the Single Reporting Platform for the same day. The address is portal.cra-srp.enisa.europa.eu.
- The CSIRT reviews the assignment in parallel. A representative whose status has not yet been verified may submit up to 20 reports.
- The full product obligations come later. The reporting obligation for open-source stewards and the complete product obligations take effect on 11 December 2027.
Related:Cyber Resilience Act: What manufacturers need to do now / NIS-2 registration: What the executive board must do now
What is the Single Reporting Platform? The Single Reporting Platform is the reporting interface of the EU agency ENISA. Actively exploited vulnerabilities and serious incidents in products with digital elements are channelled through it. Manufacturers submit there once, and ENISA and the responsible CSIRT receive the same case.
Does the reporting obligation begin on 11 September 2026?
The Federal Office for Information Security (BSI) has publicly named the deadline twice. On 26 June 2026, the BSI stated that a first stage of the Cyber Resilience Act would take effect on 11 September 2026. From that date, manufacturers of products with digital elements must report actively exploited vulnerabilities and serious security incidents affecting the product. On 5 August 2026, the authority repeated the same deadline and placed the full implementation of all requirements on 11 December 2027.
Reporting runs centrally via the European Single Reporting Platform. On 8 September 2026, ENISA updated the platform’s FAQ. Its operation has been set for the same 11 September 2026 on which Article 14 of the regulation becomes applicable. The address, registration and the parallel CSIRT review are thus described ahead of the launch.
The reporting obligation applies regardless of the product requirements that come into force in December 2027. No separate label is attached to it: according to the BSI, the CE mark will then also cover the cybersecurity requirements. A company can still ship a device under the old product rules and yet trigger a 24-hour deadline on 11 September 2026 as soon as an actively exploited vulnerability becomes known.
Routers, Sensors and Accounting Software Fall Under the Same Obligation
The first stage applies to manufacturers of products with digital elements. The BSI defines these as hardware and software that can be connected directly or indirectly to a device or a network. Networked machine controllers, sensors with firmware, routers, apps and accounting software all fall within the same framework once they are made available as a product in the Union. Non-commercial open-source products remain exempt.
For open-source stewards involved in making such products available, the reporting obligation according to ENISA only applies from 11 December 2027. Voluntary reports on vulnerabilities, threats, incidents and near misses are to be added to the platform at a later stage. At launch, the interface supports only the mandatory reports under Article 14: actively exploited vulnerabilities and severe incidents.
A single report suffices, even if the manufacturer has several branches within the Union or is based outside the EU. ENISA requires one report covering the manufacturer as a whole. Coordination between branches remains an internal matter. The case goes to the CSIRT that serves as coordinator based on the location of the main establishment. The same case is simultaneously available to ENISA. ENISA publishes the list of national coordinators separately from the reporting platform.
ENISA Allows 20 Reports Before CSIRT Verification
The platform is expected to be reachable from 11 September 2026 at portal.cra-srp.enisa.europa.eu; until then, ENISA describes the process in its FAQ. Designated representatives need a personal EU Login with multi-factor authentication. ENISA does not provide for company accounts without a named representative. Each manufacturer has one primary representative and up to 20 secondary representatives. Only the primary representative may create the association with the manufacturer and invite further representatives.
The CSIRT verifies the association in its role as coordinator without holding up the report. Only after 20 reports from a representative who has not yet been verified does ENISA require completed validation. ENISA wants registration on the platform to happen only when a report is pending, provided the EU Login already exists. The agency notes that registration takes just a few minutes once the account is in place.
The deadline begins when the manufacturer becomes aware of the issue; no authority confirmation is required for this. The deadlines are set out in the ENISA FAQ on the Single Reporting Platform dated 8 September 2026.
| Step | Deadline After Awareness | Content |
|---|---|---|
| Early Warning | 24 hours | Initial report of the actively exploited vulnerability or the severe incident |
| Notification | 72 hours | General information and initial assessment |
| Vulnerability Closure | 14 days after the fix | Final report as soon as a corrective measure is available |
| Incident Closure | one month after the 72-hour notification | Final report on the severe incident |
Source: ENISA FAQ on the Single Reporting Platform, as of 8 September 2026.
A platform outage does not lift the 24-hour deadline
ENISA states that manufacturers should wait during periods of temporary unavailability. Once the interface is back online, the report follows. An outage does not replace the obligation. A manufacturer without an account can only wait during those hours and then log in to the platform afterwards.
The EU Login is separate from the reporting interface and available even before an incident. ENISA wants to keep the number of empty manufacturer accounts small so that CSIRTs do not have to verify thousands of assignments in advance.
Does the product obligation stall until December 2027?
No. The reporting obligation applies from 11 September 2026, the product requirements from 11 December 2027. From 11 December 2027, new products with digital elements must meet the essential cybersecurity requirements before being placed on the Union market. The BSI lists risk analysis, security by design, secure defaults, a software bill of materials and security updates throughout the support period for this purpose. The bill of materials must be compiled but does not have to be published. The BSI names five years of support as the standard case; if a product is supported longer, the period extends accordingly.
An actively exploited vulnerability in a firmware component forces the same manufacturer, on 11 September 2026, to state which devices contain that component. The bill of materials the BSI mandates under the December 2027 obligations is the same overview. What remains open is whether the platform will be reachable on 11 September and when ENISA will unlock voluntary reports.
Frequently Asked Questions
From when does the reporting obligation apply?
From 11 September 2026. The BSI named this date in June and again in August 2026. ENISA is scheduling the platform’s operation for the same date.
Does the CSIRT review block the initial report?
No. The CSIRT reviews the assignment while the report is already being processed. The limit is 20 reports per manufacturer without a completed review.
Who is not yet required to report via the platform on 11 September 2026?
For open-source stewards, the reporting obligation only applies from 11 December 2027. Voluntary reports on threats or near-misses will follow in a later phase.
What applies if the platform is unavailable?
ENISA requires waiting for restoration and reporting afterwards. The outage does not lift the obligation. The EU Login can be created independently of the reporting interface.
Does the full product obligation already apply on 11 September?
No. The BSI sets the full implementation of the CRA requirements for products at 11 December 2027. The reporting obligation takes effect earlier.
Editor’s Picks
- Cyber Resilience Act: What Manufacturers Need to Do Now
- NIS-2 Registration: What the Executive Level Must Do Now
- NIS2 Implementation: A Checklist for the Mittelstand – Now
Read more on MyBusinessFuture
MyBusinessFutureWhen Every Order Email Has to be Manually Entered into the ERP SystemMyBusinessFutureInvestment backlog: How AI uncovers hidden budgetsMyBusinessFutureAI-Evaluation Before Succession: Preparing the Sales ValueMore from the MBF Media Network
cloudmagazinAWS Removes Private Preview Path to Azure AgainMyBusinessFutureKfW: Heat Pump in Demand, Yet Buying Remains the ExceptionDigital ChiefsSLB Acquires Kelvion: 3.5 Billion for AI CoolingImage source: AI-generated (September 2026)
Translated from the German original with AI support. The German version is authoritative.
