Cyber Resilience Act

CSIRT designated as coordinator

Legal definition Art. 3(51) CRA

“a CSIRT designated as coordinator pursuant to Article 12(1) of Directive (EU) 2022/2555”
Regulation (EU) 2024/2847, Art. 3(51) CRA

The CSIRT designated as coordinator is the national body to which manufacturers address their mandatory notifications under the Cyber Resilience Act (CRA). The CRA does not create it. Each Member State designates one of its computer security incident response teams as coordinator under Article 12(1) of the NIS2 Directive (Directive (EU) 2022/2555), and the CRA assigns further tasks to that same body.

For manufacturers this is the second relationship with an authority alongside market surveillance, and it starts earlier. Under Article 71(2) Article 14 applies from 11 September 2026, the remaining manufacturer obligations only from 11 December 2027. Article 69(3) adds that the Article 14 duties cover every in-scope product placed on the market before 11 December 2027 as well.

Where the role comes from

Article 12(1) of the NIS2 Directive casts the CSIRT designated as coordinator as a trusted intermediary between the person reporting a vulnerability and the manufacturer or provider of the affected product. Three tasks are named expressly:

  • identifying and contacting the entities concerned
  • assisting the natural or legal person reporting a vulnerability
  • negotiating disclosure timelines and managing vulnerabilities that affect multiple entities

Reports to the CSIRT can be made anonymously on request, and the CSIRT has to preserve that anonymity. Where a reported vulnerability could have a significant impact on entities in more than one Member State, the CSIRTs designated as coordinators cooperate within the CSIRTs network. That intermediary role explains why Coordinated vulnerability disclosure and the CRA reporting channels converge on the same body.

Which CSIRT is yours

For mandatory notifications Article 14(7) leaves no choice. The competent body is the CSIRT designated as coordinator of the Member State where the manufacturer has its main establishment in the Union. The main establishment is where decisions on the cybersecurity of the products are predominantly taken. Where no such Member State can be determined, the establishment with the highest number of employees in the Union decides.

The allocation therefore follows how product development is organised, not where the parent company sits and not where sales happen. If security ownership lives somewhere other than the legal entity, settle the question in advance. A running 24-hour deadline is the wrong moment to ask it.

What happens to a notification

An Actively exploited vulnerability and a severe Incident affecting product security go simultaneously to the competent CSIRT and to ENISA. The route is the Single reporting platform: the manufacturer submits once, through the electronic notification end-point of its CSIRT, and the platform handles distribution.

Under Article 16(2) the CSIRT that first receives the notification disseminates it without delay to the CSIRTs of the Member States in whose territory the manufacturer has indicated the product was made available. In exceptional circumstances it may delay that dissemination on justified cybersecurity-related grounds, but only for as long as is strictly necessary. It must then inform ENISA immediately, justify withholding the notification and state when it will disseminate it. Where an actively exploited vulnerability came to the CSIRT as part of a coordinated vulnerability disclosure procedure, Article 16(6) likewise allows a delay on justified cybersecurity-related grounds, for no longer than is strictly necessary and until the parties involved consent to disclosure.

Article 16(3) requires the CSIRTs to pass to the market surveillance authorities of their Member State the notified information those authorities need for their tasks under the CRA.

What the CSIRT can require of a manufacturer

Three powers are easy to miss when preparing:

  • Intermediate report. Under Article 14(6), the CSIRT that initially receives the notification may ask for an intermediate report on relevant status updates, on top of the early warning, the notification and the final report.
  • Informing users. Where the manufacturer fails to inform its users in time, Article 14(8) lets the notified CSIRTs supply that information themselves, so far as they consider it proportionate and necessary.
  • Informing the public. Where public awareness is needed to prevent or handle a severe incident, or disclosure of that incident is otherwise in the public interest, Article 17(2) allows the CSIRT to inform the public after consulting the manufacturer, or to require the manufacturer to do so. The power does not extend to vulnerabilities.

Consulting the manufacturer is mandatory. It is not a veto.

What the CSIRT does for manufacturers

The body is not only a recipient. Article 17(6) requires the CSIRTs designated as coordinators to provide helpdesk support on the Article 14 reporting obligations, expressly including support for microenterprises and small and medium-sized enterprises. Where someone other than the manufacturer reports an actively exploited vulnerability or a severe incident, Article 15(4) requires the CSIRT to inform the manufacturer without undue delay.

Article 15 also opens a voluntary route: for any vulnerability, for cyber threats that could affect a product’s risk profile, for any incident having an impact on the security of the product and for near misses that could have resulted in such an incident. The CSIRT and ENISA guarantee confidentiality and appropriate protection of what is submitted, and a voluntary notification must not create additional obligations. The CSIRT may, however, give mandatory notifications priority.

Where market surveillance takes over

The CSIRT designated as coordinator is not an enforcement authority. It orders no recall and does not rule on a product’s conformity. Those powers sit with the Market surveillance authority. Penalties are a matter for the Member States, which lay down the rules on them under Article 64(1).

That does not make the two tracks separate. Article 52(4) obliges market surveillance authorities to cooperate and exchange information regularly with the CSIRTs and ENISA when supervising the Article 14 reporting obligations. Anyone filing a notification should expect the same facts to reach market surveillance too.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.