Cyber Resilience Act
ENISA
Practical term
ENISA is the European Union Agency for Cybersecurity. The Cyber Resilience Act (CRA) neither establishes it nor defines it in Article 3; it assigns new tasks to a body that already exists. Its legal basis is Regulation (EU) 2019/881, the Cybersecurity Act.
For manufacturers the agency is above all one thing: the second recipient of every mandatory notification. Almost everything else the CRA asks of it happens without direct contact with the individual company.
Where the mandate comes from
Article 3(1) of Regulation (EU) 2019/881 describes ENISA as the reference point for advice and expertise on cybersecurity for Union institutions, bodies, offices and agencies as well as for other relevant Union stakeholders. It acts independently in carrying out its tasks. The CRA also draws on that Regulation substantively: its notion of Cybersecurity is the one in Article 2, point (1), of that Regulation.
Recipient of every mandatory notification
Article 14(1) and (3) require an actively exploited vulnerability and a severe incident to be notified simultaneously to the CSIRT designated as coordinator and to ENISA. There is no choice between the two, but there is a single route: the notification goes through the end-point of the responsible CSIRT on the Single reporting platform and is accessible to ENISA in parallel.
Article 16(2) provides for one narrow departure. In particularly exceptional circumstances ENISA first receives only an extract: the fact that a notification was made, general information about the product, the general nature of the exploitation, and the fact that security grounds were invoked. If on that basis it considers there is a systemic risk to the security of the internal market, it recommends that the receiving CSIRT forward the full notification.
Operator of the reporting platform
Article 16(1) tasks ENISA with establishing the single reporting platform and with managing and maintaining its day-to-day operation. Under paragraph 4 it takes appropriate and proportionate technical, operational and organisational measures for the platform’s security and reports any incident affecting the platform itself to the CSIRTs network and the Commission without delay. Under paragraph 5 it provides and implements the specifications for setting up, maintaining and securely operating the platform, in cooperation with the CSIRTs network.
What it does with the notifications
Article 17 names three uses that ENISA itself makes of them:
- It may pass notified information to the European cyber crisis liaison organisation network (EU-CyCLONe) where that information is relevant to the coordinated management of large-scale cybersecurity incidents and crises at operational level.
- It prepares a technical report on emerging trends in cybersecurity risks in products with digital elements every 24 months and submits it to the Cooperation Group under Article 14 of the NIS2 Directive. The first report is due within 24 months of the reporting obligations becoming applicable, so by 11 September 2028.
- It adds a notified, publicly known vulnerability to the European vulnerability database once a security update or another corrective or mitigating measure is available, and only in agreement with the manufacturer.
Alternative address for voluntary reports
Article 15 turns the relationship around. Anyone wishing to report a vulnerability, a cyber threat, an incident or a near miss voluntarily may turn to a CSIRT designated as coordinator or to ENISA. Both must ensure confidentiality and appropriate protection of the information submitted under Article 15(5), and a voluntary report may not impose additional obligations on the reporting person that would not have applied without it.
Support for market surveillance and the Commission
ENISA holds no powers over manufacturers, but it carries weight with the authorities. Under Article 52(4), market surveillance authorities cooperate and exchange information on a regular basis with the CSIRTs designated as coordinators and ENISA when supervising the reporting obligations in Article 14. Under paragraph 5 they may ask the agency for technical advice and, in an investigation under Article 54, for an analysis supporting the evaluation of a product’s compliance.
Two further routes lead from the agency back into the market. Under Article 59(2), the Commission or ENISA propose joint activities for checking compliance with the Regulation, to be carried out by market surveillance authorities. Where ENISA identifies categories of products for which sweeps may be organised, it submits a proposal for a sweep to the coordinator of the sweep under Article 60(3), for consideration by market surveillance authorities, expressly including on the basis of the notifications received under Article 14(1) and (3). Reporting therefore feeds the material that shapes inspection priorities in the years ahead.
What ENISA is not
It is not a Market surveillance authority. It does not rule on the conformity of a product and orders neither withdrawal nor recall. Penalties and administrative fines are a matter for the Member States, which lay down the rules under Article 64. Nor is it a certification body: for European cybersecurity certification schemes it prepares a candidate scheme at the Commission’s request, but the scheme itself is adopted by a Commission implementing act.
There is therefore no ENISA clearance, no ENISA mark and no binding ENISA ruling for a product with digital elements.
When this becomes real
Article 14 applies from 11 September 2026 under Article 71(2), more than a year before the Regulation applies generally on 11 December 2027. The reporting relationship with ENISA is therefore the first CRA duty that actually reaches manufacturers. By 11 September 2028 the Commission must assess the effectiveness of the reporting platform under Article 70(2), after consulting ENISA and the CSIRTs network.
Practical questions
-
No. The agency does not decide on individual products, and the CRA provides no procedure for it. Market surveillance authorities may provide guidance and advice on implementation under Article 52(10), with the support of the Commission and, where appropriate, the CSIRTs and ENISA. On the reporting obligations in Article 14, the CSIRTs designated as coordinators offer helpdesk support to manufacturers under Article 17(6), in particular to microenterprises and small or medium-sized enterprises. For a concrete question, ENISA is rarely the right address.
-
Yes. Where the Commission acts itself under Article 56(3), because a product carrying a significant cybersecurity risk remains non-compliant and market surveillance has not taken effective measures, it may ask ENISA for an analysis to support its evaluation. The economic operators concerned then have to cooperate with ENISA as necessary. Article 57(7) imposes the same duty for products that are compliant but pose the risks listed in Article 57(1), such as a risk to the health or safety of persons. Decide in advance who answers technical questions from a Union body.
-
No. Article 15 allows a voluntary report to a CSIRT designated as coordinator or to ENISA, but it does not displace the duty in Article 14. Once the manufacturer becomes aware of an actively exploited vulnerability, or of an incident that meets the threshold in Article 14(5), the 24-hour and 72-hour deadlines run regardless of any earlier voluntary report. CSIRTs may also give mandatory notifications priority over voluntary ones under Article 15(3).
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.