What are the responsibilities of key entities involved with the CRA SRP?
- Manufacturers: Submit timely notifications and comply with the other obligations established by the CRA, as per Art. 14;
- Open-source software stewards: Submit timely notifications to the extent that they are involved with products with digital elements, as per Art. 24(3);
- ENISA: Manages the platform, processes reports, prepares biennial trend reports (first due within 24 months of the reporting obligations starting), operates a helpdesk (especially for SMEs), and discloses fixed vulnerabilities to the European Vulnerability Database (EUVD);
- CSIRTs Designated as Coordinators: Receive and assess reports, decide on dissemination delays, inform market surveillance authorities and the public, if necessary, and provide helpdesk support alongside ENISA;
- European Commission: Adopts delegated and implementing acts (e.g., for delay criteria and report formats), evaluates the platform's effectiveness, and supports coordination of enforcement activities;
- Market Surveillance Authorities: Receive information from the CSIRT designated as coordinator and enforce compliance, such as through investigations or corrective actions.
© 2026
European Union Agency for Cybersecurity (ENISA)
• ENISA legal notice
• "All you need to know about the CRA SRP"
•
Disclaimer
Disclaimer: This FAQ is subject to the legal notice published on ENISA's website. Its content was extracted from ENISA's web page when this website was built; please check the original page for accuracy.