REGULATORY WATCH BRIEF Moderate 50 🧭 Regulatory Guidance announced

ENISA launches Single Reporting Platform for Cyber Resilience Act reporting

The SRP provides a single, EU‑wide tool for manufacturers to meet CRA reporting duties, enhancing coordinated cybersecurity risk management.

ImpactModerate 50
Type🧭 Regulatory Guidance
Statusannounced not law
JurisdictionEU

What happened

ENISA has deployed the initial operating capability of the Single Reporting Platform (SRP) to support the Cyber Resilience Act (CRA) reporting obligations. From 11 September 2026 manufacturers and open‑source software stewards must report actively exploited vulnerabilities and severe incidents through the SRP. The platform enables coordinated notification to national CSIRTs and ENISA.

Why it matters for trust and compliance

  • Its status is announced. It is not law yet. Track it, but do not treat it as an obligation.
  • The SRP provides a single, EU‑wide tool for manufacturers to meet CRA reporting duties, enhancing coordinated cybersecurity risk management.
  • It relates to CRA. The regulations library explains what that law requires.

Who is affected

technology controller developer platform ENISA

Recommended actions

  1. Map the security requirements to existing controls and close gaps.
  2. Schedule or refresh the risk or impact assessments this calls for.