EU launches CRA platform for exploited software flaws
ENISA has launched the Cyber Resilience Act’s Single Reporting Platform for vulnerability and severe-incident notifications.

The EU’s new Cyber Resilience Act reporting regime is now backed by a working front door. ENISA has launched the initial operating capability of its Single Reporting Platform, giving manufacturers and open-source software stewards one place to report actively exploited vulnerabilities and severe incidents affecting products with digital elements.
What's actually going on
The platform went live on 11 September 2026, the date on which the CRA’s reporting obligations begin for manufacturers. ENISA says the SRP is designed to let users report once and have the relevant information communicated to the appropriate authorities, rather than forcing companies to repeat the same notification across multiple national channels.
When a notification is first received by a coordinating Computer Security Incident Response Team, the information can be disseminated to other relevant national CSIRTs in Member States where the affected product is also available. ENISA is also notified, creating a common channel for the EU agency and national responders to coordinate around serious product-security risks.
The platform is intended for manufacturers and, where the CRA applies, open-source software stewards involved in developing products with digital elements. ENISA says the initial operating capability will continue to gain functionality as the agency gathers operational experience and feedback from users.
Why this matters
The CRA is the EU’s horizontal cybersecurity framework for products with digital elements, covering software and connected hardware across their lifecycle. The immediate change is the reporting duty: manufacturers must report actively exploited vulnerabilities and severe incidents from 11 September 2026. The Act’s broader mandatory cybersecurity requirements arrive later, from 11 December 2027.
For companies selling connected products into the European market, this turns a regulatory deadline into an operational task. Security teams need to know which incidents qualify, who owns the notification and how their internal response process connects to the SRP. Open-source stewards will need to establish where their responsibilities begin when their work forms part of a product placed on the EU market.
Our opinion
A single reporting route is a sensible answer to a problem that has traditionally involved too many forms, too many inboxes and too much uncertainty about who needs to know. The launch does not magically make CRA compliance simple, and the platform is still being expanded, but it gives manufacturers a clear place to start. If your company sells connected products in Europe, the 11 September deadline is no longer theoretical — the paperwork has arrived.
- ENISA launched the platform on 11 September 2026
- The SRP supports CRA reports from manufacturers and relevant open-source software stewards
- Reports can be shared with relevant national CSIRTs
- Broader CRA cybersecurity requirements apply from 11 December 2027