Cyber Resilience Act

Single reporting platform

Practical term

The single reporting platform is the route manufacturers use to file their notifications under the Cyber Resilience Act (CRA). Article 16 tasks ENISA with establishing it and with managing and maintaining its day-to-day operations. Its purpose appears in the same paragraph: to simplify the reporting obligations of manufacturers.

Technically it is not one portal but a federation. Its architecture must allow Member States and ENISA to put in place their own electronic notification end-points. A manufacturer therefore addresses a national end-point, and the platform handles the distribution behind it.

One notification, two recipients

Article 14 requires every Actively exploited vulnerability and every severe incident affecting product security to be notified simultaneously to the CSIRT designated as coordinator and to ENISA. The platform is the means to that end. At each stage of the Reporting obligations the manufacturer files exactly one notification, and ENISA has access to it in parallel.

That holds for all three stages alike: the early warning within 24 hours, the notification within 72 hours, and the final report.

Which end-point is the right one

Article 14(7) settles this, and the answer turns on the main establishment. You file through the end-point of the CSIRT designated as coordinator in the Member State where you have your main establishment in the Union. That is the Member State where the decisions on the cybersecurity of your products are predominantly taken. Where no such Member State can be determined, the main establishment is taken to be in the Member State where you have the establishment with the highest number of employees in the Union.

Manufacturers with no main establishment in the Union work through a fixed order:

  • the Member State of the authorised representative acting for most of the manufacturer’s products,
  • failing that, of the importer placing most of those products on the market,
  • failing that, of the distributor making most of them available,
  • failing that, the Member State with the most users.

Only in the last case does the regulation expressly allow later notifications to go to the same CSIRT. Working this out belongs well before the incident, because during one it eats hours out of the 24-hour deadline.

What happens after you send

The CSIRT that first receives the notification disseminates it without delay, via the platform, to the CSIRTs designated as coordinators in the Member States where the manufacturer has indicated the product was made available. That is why the early warning under Article 14(2), point (a), already asks which Member States the product was made available in; for severe incidents Article 14(4), point (a), asks for the same where applicable.

Those CSIRTs then provide the Market surveillance authority of their own Member State with the information it needs for its tasks under the CRA. A notification therefore does not stay within the security community. Once a security update or another corrective or mitigating measure is available, ENISA adds the notified publicly known vulnerability to the European vulnerability database under Article 17(5), in agreement with the manufacturer.

When dissemination is held back

Immediate distribution is not absolute. Under Article 16(2), dissemination may be delayed in exceptional circumstances, and in particular at the manufacturer’s request, on justified cybersecurity-related grounds, for a period no longer than strictly necessary. Where a CSIRT withholds a notification, it must immediately inform ENISA of the decision, of its reasoning, and of when it intends to disseminate. Where a Coordinated vulnerability disclosure procedure under Article 12(1) of the NIS2 Directive is running, Article 16(6) lets the CSIRT that first received the notification delay until the parties involved consent to disclosure. Which cybersecurity grounds qualify is for the Commission to set out in a delegated act under Article 14(9), by 11 December 2025.

For one narrowly drawn situation, Article 16(2) goes further: only an extract reaches ENISA at first, namely the fact that a notification was made, general information about the product, the general nature of the exploit, and the fact that security grounds were raised. That extract stands until the full notification is disseminated to the CSIRTs concerned and to ENISA. If ENISA sees a systemic risk to security in the internal market in it, it recommends to the receiving CSIRT that the full notification be disseminated.

ENISA, in cooperation with the CSIRTs network, provides the specifications for establishing, maintaining and securely operating the platform under Article 16(5). Those specifications must ensure, among other things, that where a notified vulnerability has no corrective or mitigating measure available, information about it is shared only under strict security protocols and on a “need-to-know” basis.

Voluntary reports as well

Article 16 names voluntary reports under Article 15 alongside mandatory ones as a purpose of the platform. Anyone wanting to report a vulnerability, a cyber threat, an incident or a near miss voluntarily can use the same route. Article 15 itself does not prescribe it, speaking instead of reporting to a CSIRT designated as coordinator or to ENISA. Mandatory notifications may be given priority by the CSIRT.

From when it is needed

Article 14 applies from 11 September 2026, while the regulation generally applies from 11 December 2027; Chapter IV on the notification of conformity assessment bodies (Articles 35 to 51) applies as early as 11 June 2026. The platform therefore has to be usable more than a year before the regulation generally bites. By 11 September 2028 the Commission is to assess its effectiveness under Article 70(2) in a report to Parliament and Council.

Two provisions take some of the edge off. Under Article 17(6) the CSIRTs designated as coordinators provide helpdesk support on the Article 14 reporting obligations, to manufacturers generally and in particular to those that are microenterprises or small and medium-sized enterprises. And under Article 17(4) the mere act of notifying does not expose the notifying person to increased liability.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.