💫 Recently Updated FAQs

FAQs updated within the last 14 days

When will the Single Reporting Platform be operational? Recently Updated

The platform has become operational on 11 September 2026, coinciding with the date on which the CRA reporting obligations under Art.14 are applicable.

The platform supports the mandatory reporting of actively exploited vulnerabilities and severe incidents under Art. 14 of the CRA. The corresponding reporting obligations for open-source software stewards under Art. 24(3) will apply from 11 December 2027, in accordance with Art. 71(2) of the CRA.
Voluntary reporting under Art. 15 will be introduced in a future phase of the platform.

© 2026 European Union Agency for Cybersecurity (ENISA)ENISA legal notice"All you need to know about the CRA SRP"
Disclaimer

Disclaimer: This FAQ is subject to the legal notice published on ENISA's website. Its content was extracted from ENISA's web page when this website was built; please check the original page for accuracy.

Go to page
What are the deadlines for reporting? Recently Updated

The reporting process starts when a manufacturer or open-source steward becomes aware of an actively exploited vulnerability or severe incident.

‘Actively exploited vulnerability’ means a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner (CRA definition).

‘Incident having an impact on the security of the product with digital elements’ means an incident that negatively affects (or is capable of negatively affecting) the ability of a product with digital elements to protect the availability, authenticity, integrity or confidentiality of data or functions (CRA definition).

Manufacturers and, once applicable, open-source software stewards must adhere to the following reporting deadlines:

  • Early Warning: Without undue delay and in any case within 24 hours of becoming aware of the actively exploited vulnerability or severe incident;
  • Actively Exploited Vulnerability/Severe Incident Notification: Without undue delay and in any case within 72 hours of becoming aware, providing general information and an initial assessment;
  • Final Report:
    • For actively exploited vulnerabilities: No later than 14 days after a corrective or mitigating measure (e.g., patch) becomes available.
    • For severe incidents: Within 1 month after the 72-hour notification.
© 2026 European Union Agency for Cybersecurity (ENISA)ENISA legal notice"All you need to know about the CRA SRP"
Disclaimer

Disclaimer: This FAQ is subject to the legal notice published on ENISA's website. Its content was extracted from ENISA's web page when this website was built; please check the original page for accuracy.

Go to page
What guidance material is available for the relevant parties? Recently Updated

ENISA recognises the need to ensure that manufacturers, open-source software stewards, Assigned Representatives and other relevant reporting teams have clear and practical information to use the CRA SRP. ENISA has published a range of supporting materials, including the SRP Factsheet, FAQs, User Guidance, AR User Manual, SRP Glossary and a video tutorial. These materials will be updated and expanded as necessary.

The SRP Glossary provides detailed field-by-field guidance, including what each field means, how it may be completed, the expected format, and at which reporting stage it applies.

© 2026 European Union Agency for Cybersecurity (ENISA)ENISA legal notice"All you need to know about the CRA SRP"
Disclaimer

Disclaimer: This FAQ is subject to the legal notice published on ENISA's website. Its content was extracted from ENISA's web page when this website was built; please check the original page for accuracy.

Go to page
How does the platform ensure security? Recently Updated

ENISA is legally required to take appropriate technical and organisational measures to manage risks to the platform's security and must notify the CSIRTs Network and the European Commission of any security incidents affecting the platform itself.

Before launch, the platform underwent several user, security and technical testing exercises with selected stakeholders, including national CSIRTs, the CRA Expert Group, selected manufacturers and other users. Their feedback helped strengthen the platform’s functionality, security and usability.

The platform will also be periodically reviewed and re-tested as necessary after launch.

© 2026 European Union Agency for Cybersecurity (ENISA)ENISA legal notice"All you need to know about the CRA SRP"
Disclaimer

Disclaimer: This FAQ is subject to the legal notice published on ENISA's website. Its content was extracted from ENISA's web page when this website was built; please check the original page for accuracy.

Go to page
When did the reporting obligations start? Recently Updated

The CRA reporting obligations under Art. 14 apply to manufacturers of products with digital elements from 11 September 2026.

In accordance with Art. 71(2) of the CRA, the reporting obligations for open-source software stewards under Art. 24(3) apply from 11 December 2027.

Mandatory notifications must be submitted through the CRA Single Reporting Platform. See FAQ 25 for information on what to do if the platform is temporarily unavailable.

© 2026 European Union Agency for Cybersecurity (ENISA)ENISA legal notice"All you need to know about the CRA SRP"
Disclaimer

Disclaimer: This FAQ is subject to the legal notice published on ENISA's website. Its content was extracted from ENISA's web page when this website was built; please check the original page for accuracy.

Go to page
Are open-source software stewards subject to reporting obligations under the CRA? Recently Updated

Article 24(3) of the CRA establishes that reporting obligations laid down in Article 14, paragraphs (1), (3) and (8), apply to open-source software stewards under certain circumstances.

In accordance with Article 71(2) of the CRA, Article 24(3) shall apply from 11 December 2027.

© 2025 European Union • CC-BY-4.0"FAQs on the Cyber Resilience Act" (PDF)
Disclaimer

Disclaimer: This document is prepared by the Commission services and should not be considered as representative of the European Commission's official position. The replies to the FAQs do not extend in any way the rights and obligations deriving from applicable legislation nor introduce any additional requirement. The expressed views are not authoritative and cannot prejudge any future actions the European Commission may take, including potential positions before the Court of Justice of the European Union, which is competent to authoritatively interpret Union law.

The content of this FAQ was generated from the Markdown version of the official "FAQs on the Cyber Resilience Act." As the original document was not written in Markdown, errors may have occurred during the conversion. Please check the original PDF for accuracy.

Go to page