Vulnerabilities · 5h ago
ENISA switched on the initial operating capability of its Single Reporting Platform on 11 September, as the Cyber Resilience Act’s reporting duties for manufacturers and open-source software stewards began to apply. The platform is the EU Agency for Cybersecurity’s own tool for filing reports on actively exploited vulnerabilities and severe incidents.
Instead of sending the same incident to several authorities, a reporter submits once in the portal and the coordinator CSIRT forwards it to the other Member States where the product is available, while ENISA receives it at the same time. In plain terms, the reporting path itself is now the control point, and a wrong coordinator choice can invalidate the notice and force a resubmission.
For organizations that place digital products on the EU market or steward open source software, the durable change is not a patch but a shared notification chain: one filing now creates EU-wide visibility and regulatory follow-through from the first hour. That makes incident handling a cross-border compliance process, not just an internal legal or ticketing exercise.
3 sources covering this story
The CRA Single Reporting Platform is live, and manufacturers now have 24 hours to report actively exploited vulnerabilities to EU CSIRTs.
ENISA launches Single Reporting Platform as EU Cyber Resilience Act vulnerability reporting obligations take effect.
ENISA's Cyber Resilience Act Single Reporting Platform(SRP) went live September 11, 2026 so we took a look at the new reporting platform.
Part of the PlainSec briefing for 2026-09-14