CRA SRP (Single Reporting Platform) is the sole channel for mandatory reporting under the EU Cyber Resilience Act. From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through it, within 24 hours of becoming aware.
As of 31 August 2026, the platform is not yet live. ENISA has committed to having it operational by 11 September 2026 and published step-by-step registration guidance on 31 July 2026. The public access URL will be published on ENISA’s SRP page before go-live and has not yet appeared.
The list of national CSIRTs designated as coordinators is still outstanding, which sits awkwardly with a registration flow that asks you to select your designated CSIRT from a drop-down.
Three practical points determine whether 11 September is uneventful for your organisation.
- EU Login accounts can be created now and should be. Nobody should be creating an account during an incident.
- ENISA advises registering on the SRP itself only when you have a specific notification to submit, to avoid overloading national teams before launch. This is the opposite of the advice circulating in most compliance content.
- There is no reporting API. Internal workflow can be automated up to the point of submission, but a human will be typing into a browser at the end of it.
This guide covers what the platform does, who registers and how, what the reporting clocks require, what remains unresolved, and what to prepare in the time remaining.

CRA SRP: Key Definitions
| Term | Definition |
|---|---|
| SRP | Single Reporting Platform. The ENISA-operated central intake system for CRA reporting, established under Article 16 |
| CRA | Cyber Resilience Act, Regulation (EU) 2024/2847 |
| Assigned Representative (AR) | The SRP account role for a user who files on behalf of a manufacturer or open source steward. Distinct from a CRA authorised representative appointed by written mandate |
| CSIRT | Computer Security Incident Response Team. The national body designated as coordinator, which receives the notification first |
| ENISA | European Union Agency for Cybersecurity. Operates the SRP |
| Actively exploited vulnerability | A vulnerability for which there is reliable evidence of malicious execution against a system without the owner’s permission |
| Severe incident | An incident negatively affecting the security of a product with digital elements |
| EU Login | The European Commission’s authentication service, used to access the SRP |
| Open source software steward | A legal person supporting open source development on a sustained basis without directly monetising it. Also subject to reporting obligations |
What Is the Single Reporting Platform
Article 16 of the CRA tasks ENISA with establishing the Single Reporting Platform (SRP). Its purpose is consolidation: manufacturers submit a notification once and the platform routes it to the appropriate authorities rather than requiring parallel filings to multiple national bodies.
The routing logic works on establishment. A notification goes first to the CSIRT designated as coordinator, being that of the member state where the manufacturer has its main establishment, or where the manufacturer is outside the EU, the member state of its authorised representative. The SRP simultaneously makes the notification available to ENISA and supports dissemination to other relevant national CSIRTs.
CRA SRP is a single intake point, not a single recipient. The manufacturer files once. The platform distributes. The submission channel is exclusive. Reports go through the CRA SRP, not by ordinary email to a national authority.
Current CRA SRP Status
ENISA launched a public tender and procured contractor services to develop the SRP. Functional and security testing are under way. The platform is scheduled to be operational by 11 September 2026, the date the Article 14 reporting obligations enter into application.
| Item | Status as at August 2026 |
|---|---|
| Platform operational | Not yet. Scheduled for 11 September 2026 |
| Public access URL | Not published. Will appear on ENISA’s SRP page before go-live |
| Registration guidance | Published 31 July 2026. Marked subject to change |
| SRP FAQ | Published by ENISA |
| List of designated national CSIRTs | Still outstanding |
| Reporting API | Not provided at this stage |
| Voluntary reporting | Enabled only after 11 September 2026 |
| Support address | cra-srp-helpdesk@enisa.europa.eu |
ENISA marks its guidance as reflecting current best knowledge and subject to change. Verify against the official ENISA SRP page before treating any specific step as final.
Who Registers at CRA SRP
| Party | Registration required |
|---|---|
| Manufacturer of in-scope products | Yes |
| Open source software steward | Yes, to the extent involved in product development |
| Importer | No, if the manufacturer is registered |
| Distributor | No, if the manufacturer is registered |
| Non-EU manufacturer | Yes, through its EU authorised representative |
The Assigned Representative role is worth understanding precisely because the terminology collides. ENISA calls the SRP user who files on behalf of a manufacturer an Assigned Representative. That is a platform account role. It is not the same thing as a CRA authorised representative appointed by written mandate under Article 17, though the same person may hold both.
The platform provides two seats: a Primary representative and a Secondary who joins by email invitation and holds a backup role. The invitation link expires after seven days, after which the record is marked “Invitation Expired” and the invitation must be reissued.
CRA SRP Registration Flow
Registration runs through EU Login. The step sequence published by ENISA on 31 July 2026 is as follows.
| Step | Action |
|---|---|
| 1 | Create or verify an EU Login account |
| 2 | Access the SRP and select your role |
| 3 | Select your designated CSIRT from a drop-down |
| 4 | Accept the legal agreement |
| 5 | Confirm pre-filled personal details |
| 6 | Enter the manufacturer’s name, address, and additional information |
| 7 | Invite the Secondary representative by email within seven days |
Step 6 creates the manufacturer entity in the platform. Step 3 is where the outstanding CSIRT list creates friction: the flow asks you to pick your designated CSIRT from a list that has not yet been finalised.
The timing point that catches people out. ENISA advises manufacturers to register on the SRP and start validation only when they have a specific notification to submit, so as not to overload national teams before launch. This runs against the instinct to complete registration early.
The distinction that resolves it: create your EU Login account now, for the primary filer and at least one deputy. That involves no CSIRT, no queue, and no approval. SRP registration itself is a separate step that ENISA prefers you defer until you have something to file.
CRA Reporting Clocks
Two events trigger a report: an actively exploited vulnerability in your product, and a severe incident affecting its security.
| Stage | Deadline (vulnerability) | Deadline (severe incident) | Content |
|---|---|---|---|
| Early warning | 24 hours from awareness | 24 hours from awareness | That the vulnerability or incident exists and, if known, the affected member states |
| Notification | 72 hours from awareness | 72 hours from awareness | General information on the affected product, nature of the issue, corrective or mitigating measures available |
| Final report | No later than 14 days after a corrective measure is available | Within one month of the 72-hour notification | Full description, severity, impact, corrective measure deployed |
The clocks run in elapsed hours, not working days. A vulnerability disclosed on a Friday evening does not wait for Monday.
Article 16(2) allows a manufacturer to flag narrow conditions in its 72-hour notification, which limits what ENISA sees until the coordinating CSIRT releases the full text. In exceptional circumstances, dissemination may be delayed under Article 16 and Delegated Regulation (EU) 2026/881. A dissemination delay restricts content, not timing. Your submission deadline does not move.
CRA SRP: The Absent API
ENISA states that no reporting API will be provided at this stage. This is the single most consequential operational detail for larger manufacturers and it has received little attention.
Internal workflow can be automated up to the point of submission. Vulnerability detection, SBOM matching, severity assessment, internal escalation, and drafting can all be systematised. The final step is a human in a browser.
This has two implications. First, the named individuals who hold SRP access are a single point of failure in a 24-hour process. Both the Primary and Secondary seats should be filled, and both people should have used the interface before they need it.
Second, the internal process must terminate in a submission-ready package rather than a partially assembled one. If your automated pipeline produces an assessment that still requires half an hour of manual assembly before it can be typed into the platform, that half hour comes out of your 24 hours.
What Is Still Outstanding at CRA SRP
Three items remain unresolved as at late August 2026.
The public access URL. Not published. ENISA will post it on its SRP page before go-live. Any URL circulating before that is not authoritative.
The designated CSIRT list. Member states designate the CSIRT that acts as coordinator. The consolidated list has not been published, which is difficult to reconcile with a registration flow requiring you to select yours.
Notification format and procedure. The Commission may still specify notification formats and procedures by implementing act. ENISA’s current screens and end-points remain subject to its own specifications.
None of this prevents preparation. All of it prevents treating any specific interface step as settled.
What to Prepare Now
The following can be completed without CRA SRP access.
Create EU Login accounts. For the primary filer and at least one deputy. This involves no CSIRT, no queue, and no approval, and nobody should be doing it during an incident.
Name the Primary and Secondary Assigned Representatives. Two named people with the authority to file, both of whom will have used the interface before a live report.
Identify your main place of establishment and your coordinating CSIRT. For non-EU manufacturers, this follows your authorised representative’s establishment. Resolve it before you need it.
Assemble the organisational data. Legal organisation name, registered address, manufacturer entity details, and contact information. Missing these will slow a first submission.
Define who starts the 24-hour clock. The clock runs from awareness. Someone in your organisation has to be authorised to declare that awareness has occurred and to trigger the process. Ambiguity here is where the hours go.
Define who approves submission. Separate from who starts the clock. A submission going out requires a decision, and the decision-maker needs to be reachable outside business hours.
Prepare the data template. Product identification, vulnerability or incident description, impact assessment, affected versions, affected member states where known, and available mitigations. Draft the 24-hour, 72-hour, and final report templates in advance.
Rehearse the handoffs. Walk a hypothetical vulnerability end-to-end. The first time your team runs the process should not be in production.
Build the SBOM connection. You cannot determine within 24 hours whether a newly published CVE affects your product without a current component inventory matched against vulnerability feeds. The SBOM obligation under Annex I is not enforceable until December 2027, but the reporting obligation makes it operationally necessary from September 2026.
Penalties for Failure to Report
Failure to comply with the Article 14 reporting obligations is a breach of manufacturer obligations. The penalty ceiling is €10 million or 2% of global annual turnover, whichever is higher.
The CRA does not penalise reasonable over-reporting. Where you genuinely do not know whether a vulnerability is being actively exploited, filing the early warning is the safer position. Honest interpretation is treated differently from wilful concealment.
Prepare Your CRA Documentation With European Compliance Suite
European Compliance Suite produces CRA documentation packs for manufacturers of products with digital elements, covering the artefacts you need before 11 September 2026 and ahead of full application in December 2027.
The CRA Vulnerability Reporting Pack covers the operational documentation the September deadline requires: incident and vulnerability reporting procedure, the 24-hour, 72-hour, and final report templates, an escalation and on-call runbook, the awareness declaration and submission authority matrix, and an SRP registration data sheet holding the organisational information the platform will ask for.
The CRA Template Pack covers the latest requirements: Annex I gap assessment templates, SBOM policy and format specification, vulnerability handling process documentation, support period definition and criteria, technical documentation structure, and the EU declaration of conformity template.
The CRA Supply Chain Pack (coming soon, available by request) covers the contractual layer: supplier SBOM provision clauses, patching commitment and notification obligations, end-of-life dependency assessment templates, and third-party component vulnerability handling procedures.
Each pack is drafted against the regulation text and structured so that the documents work together rather than as isolated templates. They are written for manufacturers who need to be able to answer a market surveillance authority, not to populate a compliance folder.
Contact European Compliance Suite to discuss which pack fits your product classification and timeline.
FAQ
What is the CRA Single Reporting Platform?
The Single Reporting Platform is ENISA’s central intake system for mandatory reporting under the Cyber Resilience Act, established under Article 16. From 11 September 2026, manufacturers submit notifications of actively exploited vulnerabilities and severe incidents through it, and the platform routes them to the relevant national CSIRT and to ENISA.
When does the Single Reporting Platform go live?
11 September 2026, the date the Article 14 reporting obligations enter into application. ENISA has scheduled the platform to be operational by that date, with functional and security testing under way. The public access URL will be published on ENISA’s SRP page before go-live.
Can we register on the SRP now?
You can create your EU Login account now and should. ENISA advises registering on the SRP itself and starting validation only when you have a specific notification to submit, to avoid overloading national teams before launch. The EU Login account is the part to complete in advance.
Is there an API for CRA reporting?
No. ENISA states that no reporting API will be provided at this stage. Internal workflow can be automated up to the point of submission, but the final submission is made through a browser interface by a human user.
Who needs to register on CRA SRP?
Every manufacturer of in-scope products with digital elements, and open source software stewards to the extent they are involved in product development. Importers and distributors do not need their own registration if the manufacturer is registered. Non-EU manufacturers register through their EU authorised representative.
What is an Assigned Representative on the SRP?
The SRP account role for the user who files on behalf of a manufacturer or open source steward. It is a platform role, distinct from a CRA authorised representative appointed by written mandate under Article 17, though the same person may hold both. The platform provides a Primary and a Secondary seat.
Which CSIRT do we report to?
The CSIRT designated as coordinator in the member state where you have your main establishment, or where you are established outside the EU, the member state of your authorised representative. The consolidated list of designated national CSIRTs has not yet been published.
What are the CRA reporting deadlines?
An early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report no later than 14 days after a corrective measure is available for a vulnerability, or within one month of the 72-hour notification for a severe incident. The clocks run in elapsed hours.
What happens if we report something that turns out not to be actively exploited?
The CRA does not penalise reasonable over-reporting. Where you genuinely cannot determine whether a vulnerability is being actively exploited within the 24-hour window, filing the early warning is the safer course. The regulation distinguishes honest interpretation from wilful concealment.
What is the penalty for failing to report?
Failure to comply with the reporting obligation is a manufacturer-obligation breach, carrying a ceiling of €10 million or 2% of global annual turnover, whichever is higher.
Do we need an SBOM before September 2026?
Not as a legal obligation. The Annex I SBOM requirement is enforceable from 11 December 2027. Operationally, determining within 24 hours whether a published vulnerability affects your product is not realistic without a current component inventory. The SBOM is a practical prerequisite for the September obligation even though it is not a legal one until 2027.
Does the SRP replace national reporting channels?
For CRA reporting, yes. Submissions go through the SRP rather than by email to a national authority. The SRP routes to the coordinating CSIRT and makes the notification available to ENISA. Reporting obligations under other instruments, including NIS2 and GDPR, run through their own channels and are not consolidated into the SRP.
Legal Disclaimer
This guide reflects Regulation (EU) 2024/2847, Delegated Regulation (EU) 2026/881, ENISA guidance published to 31 July 2026, and the status of the Single Reporting Platform as at late August 2026. ENISA marks its guidance as subject to change and the platform URL, designated CSIRT list, and notification format specifications remain outstanding. Verify against the official ENISA SRP page before relying on any specific interface step. This guide is published by European Compliance Suite for general informational purposes and does not constitute legal advice.
