The European Union Agency for Cybersecurity, ENISA, has announced the launch of the initial operational capability of the Single Reporting Platform, the European system designed to handle reports required under the Cyber Resilience Act for actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements. The launch moves from the legal framework of the new European reporting obligations to the technical infrastructure through which those obligations can be managed. The platform is operated by ENISA and is designed so that notifications can be submitted through a common system at European Union level.
What is the Single Reporting Platform?
The Cyber Resilience Act introduces cybersecurity requirements for a broad range of products with digital elements made available on the European Union market. These can include both hardware and software where they fall within the scope of the regulation. One important component is the requirement for manufacturers to report certain actively exploited vulnerabilities and severe incidents. The Single Reporting Platform was created to handle those reports: rather than a fragmented system, it provides European infrastructure through which notifications can be submitted once and distributed to competent authorities.
Why the launch matters
The regulation's reporting obligations begin to apply on 11 September 2026. An operational infrastructure for submitting notifications is therefore necessary for the new requirements to function in practice. ENISA developed, operates and maintains the platform. Information on vulnerabilities and incidents is handled with confidentiality safeguards. At launch, the system covers manufacturers' mandatory notifications; ENISA said it will continue to expand functionalities in the coming months.
What must be reported?
The Cyber Resilience Act does not require every vulnerability discovered in a product to be immediately reported. Specific obligations cover actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements, according to the criteria in the regulation. For an actively exploited vulnerability, a manufacturer must submit an early warning without undue delay and, in any event, within 24 hours of becoming aware of it. The process does not end with the initial warning: subsequent stages provide authorities with more detailed information, including a main notification and a final report after remedial measures. Severe incidents are also subject to a staged notification process.
24 hours does not mean 24 hours to fix the problem
The initial 24-hour deadline concerns notification under the regulation, not complete remediation of the vulnerability. Investigating the cause, developing an update and distributing it to users may require additional time. Rapid notification is intended to ensure that relevant authorities are informed when an actively exploited vulnerability may present a significant security risk.
A common European system
ENISA plays the central technical role, and information is distributed according to the mechanisms in the Cyber Resilience Act. Once a notification is submitted, the national CSIRT designated as coordinator disseminates it to other CSIRTs in Member States where the product is available, while the notification is simultaneously made available to ENISA. Digital products are frequently marketed across several member states, so a vulnerability can have cross-border consequences. A common European mechanism can facilitate coordination when a security problem emerges.
Which products are covered?
The regulation uses the concept of products with digital elements. Broadly, it covers hardware and software within its scope that are made available on the European Union market. It should not be interpreted as applying exclusively to software applications. The regulation also contains exemptions and interacts with other legal frameworks, so applicability must be assessed for each product category.
Open source and the application timetable
The Cyber Resilience Act distinguishes between non-commercial open-source development and commercial activities involving software products. It would be inaccurate to suggest that every developer publishing free open-source code automatically becomes subject to all obligations imposed on a commercial manufacturer. ENISA also notes that reporting obligations for open-source software stewards, to the extent provided by Article 24(3), apply from 11 December 2027, not from today's launch.
A further distinction is needed on the overall timetable. The Cyber Resilience Act is already European law, but different provisions have different application dates. Reporting obligations begin on 11 September 2026. Most of the regulation's general requirements are scheduled to apply from 11 December 2027. The platform launch should not be presented as though every CRA requirement becomes applicable simultaneously in September 2026.
For manufacturers subject to the reporting obligations, the European mechanism is no longer only a future requirement. From 11 September 2026 it becomes a concrete part of how actively exploited vulnerabilities and severe incidents are handled. For end users, the effects of the platform may not be directly visible; the objective is to allow information about serious security problems to move more rapidly between manufacturers and competent authorities.
Source consulted: The CRA Single Reporting Platform is launched (ENISA, 11 September 2026). Legislative context: Cyber Resilience Act — Reporting obligations (European Commission). Image: official ENISA graphic for the CRA Single Reporting Platform launch, September 2026.
0 Comments
No comments on this article yet. Be the first!