ENISA launches Single Reporting Platform for Cyber Resilience Act reporting
The SRP provides a single, EU‑wide tool for manufacturers to meet CRA reporting duties, enhancing coordinated cybersecurity risk management.
ADTP Regulatory Watch· September 11, 2026· ENISA
ImpactModerate 50
Type🧭 Regulatory Guidance
Statusannouncednot law
JurisdictionEU
What happened
ENISA has deployed the initial operating capability of the Single Reporting Platform (SRP) to support the Cyber Resilience Act (CRA) reporting obligations. From 11 September 2026 manufacturers and open‑source software stewards must report actively exploited vulnerabilities and severe incidents through the SRP. The platform enables coordinated notification to national CSIRTs and ENISA.
Why it matters for trust and compliance
Its status is announced. It is not law yet. Track it, but do not treat it as an obligation.
The SRP provides a single, EU‑wide tool for manufacturers to meet CRA reporting duties, enhancing coordinated cybersecurity risk management.
It relates to CRA. The regulations library explains what that law requires.
Who is affected
technologycontrollerdeveloperplatformENISA
Recommended actions
Map the security requirements to existing controls and close gaps.
Schedule or refresh the risk or impact assessments this calls for.