15.09.2026

Today marks an important milestone in the implementation of the EU Cyber Resilience Act (CRA): the reporting obligations under Article 14 have entered into application.

To support manufacturers and open-source software stewards in meeting these obligations, the European Union Agency for Cybersecurity (ENISA), in cooperation with the CSIRT Network, has launched the Single Reporting Platform (SRP**) **(as required under article 16 of CRA). ENISA has also created an informationpage with tutorials to help users get started.

The SRP is designed to facilitate reporting of:

  • Actively exploited vulnerabilities affecting products with digital elements; and
  • Severe security incidents affecting such products.

The platform provides a single point through which manufacturers and other entities subject to the reporting obligations can submit information and communicate it to the relevant authorities.

Further clarifications on reporting obligations are also contained in Section 9.1 of the Commission guidance on the CRA, as well as in Section 5 of the Commission's Frequently Asked Questions on the CRA implementation.

Date: 15.09.2026

Source: BUSINESSEUROPE

Readed: 89