The EU Agency for Cybersecurity (ENISA) has switched on the first working version of its Single Reporting Platform (SRP), the tool manufacturers and open-source software stewards now have to use to meet a new mandatory reporting duty under the EU Cyber Resilience Act (CRA). That duty took effect on September 11, 2026: from that date, any manufacturer or open-source steward whose connected product is available on the EU market must report actively exploited vulnerabilities and severe incidents affecting that product, and the SRP is the single channel built to receive those reports. The platform lets an organization submit one notification that then gets distributed to every relevant national authority automatically, rather than requiring separate reports to each Member State where the product is sold.

Mechanically, the reporting flow works like this: a manufacturer submits a notification, it goes first to whichever national Computer Security Incident Response Team (CSIRT) is designated as the coordinator for that submission, that CSIRT then disseminates the information to other relevant CSIRTs in any Member State where the affected product is also available, and ENISA itself receives the notification in parallel. This is explicitly designed to close the gap where a single vulnerability disclosure would otherwise need to be manually repeated across multiple national regulators, and it gives ENISA and national CSIRTs a more complete, near-real-time picture of what’s actively being exploited across the EU’s connected-product landscape. Reporting obligations for open-source software stewards specifically, under Article 24(3) of the CRA, follow a slightly later timeline and apply from December 11, 2027, alongside the CRA’s broader cybersecurity requirements.

It's worth being precise about what this platform is and isn't. The SRP is distinct from the European Vulnerability Database (EUVD), an earlier ENISA tool mandated under NIS2 that centralizes general vulnerability information and mitigation guidance for public consumption. The SRP instead is the confidential regulatory reporting channel specifically for the CRA's 24-hour actively-exploited-vulnerability and severe-incident notification duty, built with security measures to protect the confidentiality of submitted information. ENISA has published an FAQ, user manuals, tutorial videos, a glossary, and a factsheet in multiple EU languages to support manufacturers navigating the new obligation, alongside a dedicated help desk for questions the published guidance doesn't cover. ENISA has also separately created an SME Cyber Resilience Maturity Assessment Model aimed at helping smaller organizations, who often lack dedicated compliance staff, identify gaps and prepare for CRA obligations at a practical level.

For security staff at a company serving EU or Danish public-sector clients, this launch is directly operational rather than background regulatory news. Any team that builds or maintains a connected product, or supports one that does, needs to know whether the September 11 reporting clock now applies to their organization, and if so, how their existing vulnerability disclosure and incident response processes feed into a 24-hour reporting window through the SRP rather than assuming existing NIS2 or GDPR notification timelines cover it. Practically, this means reviewing incident response runbooks to make sure someone on the team knows the SRP exists, understands the CSIRT coordinator handoff process, and has a clear internal escalation path the moment an actively exploited vulnerability is confirmed, since the 24-hour clock starts from the point of discovery, not from when a formal review process concludes.