I am not a manufacturer. How can I report a vulnerability or security issue?

The current version of the platform supports only mandatory notifications submitted by manufacturers under Art. 14 of the CRA. If you are not a manufacturer and would like to report a vulnerability or other security issue, please contact the relevant national CSIRT directly. Your submission might be marked as ‘invalid’ in the SRP.

© 2026 European Union Agency for Cybersecurity (ENISA)ENISA legal notice"All you need to know about the CRA SRP"
Disclaimer

Disclaimer: This FAQ is subject to the legal notice published on ENISA's website. Its content was extracted from ENISA's web page when this website was built; please check the original page for accuracy.