How do I know which national CSIRT I should report to through the CRA SRP?

Manufacturers and, once applicable, open-source software stewards are responsible for identifying the correct CSIRT designated as coordinator (CDaC) in accordance with Art. 14(7) of the CRA and selecting it when submitting a notification through the SRP. If the wrong CDaC is selected, the notification may be invalidated and will need to be resubmitted to the correct CDaC.

In general, you should report to the CDaC in the Member State of your main establishment in the EU. Under the CRA, the main establishment is the place where decisions related to the cybersecurity of your products with digital elements are predominantly taken.

If this cannot be determined, use the Member State where your establishment with the highest number of employees in the EU is located.

If you do not have a main establishment in the EU, determine the relevant Member State using the following order, based on the information available:

You should then select the corresponding CDaC when submitting your notification through the SRP.

© 2026 European Union Agency for Cybersecurity (ENISA)ENISA legal notice"All you need to know about the CRA SRP"
Disclaimer

Disclaimer: This FAQ is subject to the legal notice published on ENISA's website. Its content was extracted from ENISA's web page when this website was built; please check the original page for accuracy.