ENISA Introduces Mandatory Cyber Vulnerability Reporting Platform
The European Union Agency for Cybersecurity (ENISA) has officially launched its Cyber Resilience Act (CRA) Single Reporting Platform (SRP). This significant new cybersecurity compliance tool was activated on September 11, 2026, coinciding with the enforcement of binding reporting obligations for manufacturers throughout the EU.
As per the new regulations under the Cyber Resilience Act (Regulation EU 2024/2847), any company introducing a product with digital components in the EU market is now required to report actively exploited vulnerabilities and severe security incidents through this centralized portal. The reporting timeline is stringent:
- An early warning must be filed within 24 hours of the manufacturer becoming aware of a security event,
- A more detailed notification within 72 hours,
- And a final report within 14 days of a corrective measure becoming available.
The SRP serves as a single electronic entry point, simultaneously routing notifications to the national Computer Security Incident Response Team (CSIRT) in the manufacturer’s home country and to ENISA. This coordinated strategy aims to ensure quicker EU-wide responses to security threats. ENISA, under Article 16(1) of the CRA, maintains and operates the platform. The primary cybersecurity requirements of the CRA will be applicable to manufacturers from December 11, 2027.
