Current-state note. ENISA launched the initial operating capability of the CRA Single Reporting Platform on 11 September 2026, the same date Article 14 reporting obligations became applicable to manufacturers.

The portal is live. The hard part is upstream.

From 11 September 2026, manufacturers of products with digital elements must use ENISA’s Single Reporting Platform for mandatory notifications of actively exploited vulnerabilities and severe incidents under Article 14 of the Cyber Resilience Act. ENISA describes the SRP as a report-once mechanism: the manufacturer selects the relevant coordinating CSIRT, and the notification can then be made available to ENISA and disseminated to other relevant authorities.

That removes routing friction. It does not remove the operational problem that precedes submission. Before a manufacturer can make a defensible notification, it still has to establish which product and versions are affected, whether exploitation meets the CRA trigger, what is known about impact and mitigation, and who owns the regulatory decision.

The reporting clock measures evidence latency

The engineering metric that matters is therefore not portal completion time. It is evidence latency: how long it takes to move from an external or internal vulnerability signal to a product-scoped, reviewable decision.

A usable operating model links product identity, deployed software versions, component inventory, supplier ownership, exploitability assessment, mitigations and decision authority. SBOM and VEX can support that chain, but neither replaces product-specific analysis or accountable judgement.

The practical test is whether the organisation can produce a bounded statement while some evidence is still incomplete, preserve the uncertainty explicitly, and update the record as stronger evidence arrives.

The SRP centralises notification. CRA readiness still depends on how quickly an organisation can turn incomplete technical evidence into an owned product decision.
The decision
Measure and rehearse evidence latency from vulnerability signal to regulatory decision, not only the mechanics of submitting the SRP form.
Operational checks
  • Map every regulated product to versions, components and responsible owners.
  • Define the trigger and owner for the first exploitability assessment.
  • Predefine escalation authority for the 24-hour decision window.
  • Record uncertainty, assumptions and supplier dependencies explicitly.
  • Exercise the workflow end to end before a real notification.
Source record

Sources & further reading

3 cited sourcesHow we source →
← All analysis
Where to go next

Continue this decision.

Choose the next decisionContinue through a guided Reading Path

Move from this analysis into a curated route across related incidents, evidence and operating constraints.

→