ENISA Activates Mandatory Cyber Resilience Reporting Platform
The European Union Agency for Cybersecurity (ENISA) has officially launched its highly anticipated Cyber Resilience Act (CRA) Single Reporting Platform (SRP). This pivotal digital tool was activated on September 11, 2026, coinciding with the enforcement of the EU’s new mandatory reporting obligations for manufacturers throughout Europe and beyond.
Under these new regulations, any company introducing a product with digital components into the EU market — ranging from consumer electronics to enterprise software — is now obligated to report actively exploited vulnerabilities and severe security incidents directly through this centralized portal. The reporting timeline is stringent: an early warning within 24 hours of identifying an issue, a more comprehensive notification within 72 hours, and a final report within 14 days of a corrective measure becoming available.
The SRP aims to simplify compliance by enabling manufacturers to submit a single notification that is automatically forwarded to the relevant national Computer Security Incident Response Team (CSIRT) and to ENISA simultaneously. The platform fosters a more unified EU-wide approach to cybersecurity risk management. The CRA’s more extensive cybersecurity requirements for product design will be enforced from December 11, 2027.
