How do I know which national CSIRT I should report to through the CRA SRP?
Manufacturers and, once applicable, open-source software stewards are responsible for identifying the correct CSIRT designated as coordinator (CDaC) in accordance with Art. 14(7) of the CRA and selecting it when submitting a notification through the SRP. If the wrong CDaC is selected, the notification may be invalidated and will need to be resubmitted to the correct CDaC.
In general, you should report to the CDaC in the Member State of your main establishment in the EU. Under the CRA, the main establishment is the place where decisions related to the cybersecurity of your products with digital elements are predominantly taken.
If this cannot be determined, use the Member State where your establishment with the highest number of employees in the EU is located.
If you do not have a main establishment in the EU, determine the relevant Member State using the following order, based on the information available:
- the Member State where your authorised representative acts on your behalf for the highest number of products with digital elements;
- if this does not apply, the Member State where the importer places the highest number of your products with digital elements on the market;
- if this does not apply, the Member State where the distributor makes the highest number of your products with digital elements available on the market;
- if none of the above applies, the Member State with the highest number of users of your products with digital elements.
You should then select the corresponding CDaC when submitting your notification through the SRP.
Disclaimer
Disclaimer: This FAQ is subject to the legal notice published on ENISA's website. Its content was extracted from ENISA's web page when this website was built; please check the original page for accuracy.