Regulation (EU) 2024/2847 · Articles 14, 15 and 16

The ENISA Single Reporting Platform

The SRP is the single entry point for CRA notifications. A manufacturer files once and the platform delivers to the coordinating CSIRT and ENISA at the same time. It carries a mandatory channel for the Article 14 cascade and a voluntary channel open to anyone. This page covers what it collects at each stage, who may file on which channel, and the four things it does not do.

What the SRP is, in one paragraph

Article 16 of the Cyber Resilience Act establishes a single reporting platform to simplify manufacturers' reporting obligations. Article 16(1) has the platform established by ENISA and its day-to-day operations managed and maintained by ENISA, with Member States and ENISA putting in place their own electronic notification end-points. You submit through the end-point of your coordinating CSIRT, and Article 14(7) makes that submission simultaneously accessible to ENISA. Under Article 16(2) the receiving CSIRT then disseminates it to the coordinating CSIRTs of the territories where you indicated the product is available. The mandatory channel carries the Article 14 cascade, an early warning within 24 hours, a full notification within 72 hours and a final report. A separate voluntary channel under Article 15 is open to any person and accepts a wider set of report types. The platform is scheduled to be operational by 11 September 2026.

Filing once sounds simple, and it is simple only if you can produce the required fields under a clock that started the moment you became aware. That is where the preparation goes.

Two channels, different rules

The mandatory channel is narrow and binds manufacturers. The voluntary channel is wide and binds nobody. Collapsing the two is the most common misreading of the platform.

Mandatory

Article 14
Who may file
Manufacturers, and open-source software stewards where they are involved with products with digital elements.
What it accepts
Actively exploited vulnerabilities contained in the product, and severe incidents having an impact on the security of the product. A high bar on both counts.
When
From 11 September 2026, the date the platform is scheduled to be operational.

Voluntary

Article 15
Who may file
Any natural or legal person. Security researchers, downstream integrators, customers and other vendors all qualify.
What it accepts
Vulnerabilities in general rather than only exploited ones, cyber threats affecting a product's risk profile, incidents below the severe threshold, and near misses that could have become an incident.
When
ENISA has indicated the voluntary function arrives after the mandatory channel rather than alongside it.

What the form collects, by stage

ENISA marks each field to show how it behaves as a report matures. A field that is mandatory at 24 hours becomes a confirmed field later, and a field that is optional at 24 hours often becomes mandatory at 72 hours once you have had time to assess.

XMandatory

A core requirement at that stage. The report is incomplete without it.

CConfirmed

The value given earlier is carried forward, then confirmed or refined at the later stage.

OOptional

Provide it if you have it. Not required at that stage.

AAutomated

The platform fills it for you, typically a timestamp or the reporter identity.

IInformational

Provided if applicable to the notification.

Fields common to every notification

Field24h72hFinal
Notification type (vulnerability or incident)MandatoryConfirmedConfirmed
Notification level (24h, 72h, final)MandatoryMandatoryMandatory
Reporting time and reporter identityAutomatedAutomatedAutomated
Name of manufacturer or open-source stewardMandatoryConfirmedConfirmed
ProductMandatoryConfirmedConfirmed
Product type (default, important, critical)OptionalConfirmedConfirmed
Product category (Annex III or IV, if not default)OptionalConfirmedConfirmed
Member States where the product is availableIf applicableConfirmedConfirmed
TitleMandatoryConfirmedConfirmed

The early warning is genuinely lightweight, which is the design. Vulnerability notifications then add exploitation and identifier fields, and incident notifications add nature, assessment and root-cause fields. The full field map covers both branches stage by stage.

What happens after you file, and when it is held back

The receiving CSIRT disseminates your notification onward without delay by default. Article 16(2) then builds in an exception that most summaries of the platform leave out entirely.

Dissemination can be delayed on request

In exceptional circumstances, and in particular on the manufacturer's request in light of the sensitivity indicated under Article 14(2), point (a), the coordinating CSIRT may delay onward dissemination on justified cybersecurity-related grounds, for a period strictly necessary. A vulnerability under a coordinated disclosure procedure per Article 12(1) of the NIS2 Directive is named as a case where this applies.

A withholding CSIRT must answer to ENISA

Where a CSIRT decides to withhold, it must immediately inform ENISA of the decision, provide a justification, and indicate when it will disseminate. ENISA may support the CSIRT on applying the cybersecurity grounds. The delay is a supervised exception rather than a discretionary pause.

A narrower gate exists for single-Member-State exploitation

Article 16(2) adds a particularly exceptional tier where the manufacturer indicates under Article 14(2), point (b), that the vulnerability has been actively exploited by a malicious actor and, per the information available, in no Member State other than the one notified, or that further dissemination would supply information contrary to that Member State's essential interests.

The practical consequence is that the sensitivity indication on your 24-hour filing is a real lever. It is the input the withholding decision is weighed against, so it deserves a considered answer rather than a default one.

Four things the SRP does not do

The platform is an exit point. Everything that decides whether you reach it happens on your side first.

1

There is no manufacturer submission API

Article 14(7) routes notifications through the platform, and ENISA does not currently expose a submission API for manufacturers. The filing itself is a manual step whatever tooling sits behind it. Any vendor claiming automatic filing to the SRP is describing something the platform does not offer.

2

The SRP does not decide whether you must report

The awareness judgement, the active exploitation finding and the severity assessment all happen on your side before the platform is involved. The SRP receives a decision you have already made and starts no clocks of its own.

3

It does not replace your Article 13 obligations

The single point of contact, the coordinated vulnerability disclosure policy and the intake channel that tells you a thing is being exploited are all your responsibility. The SRP is the exit, and it presumes the entrance already exists.

4

It does not report for you under NIS2 or GDPR

One event can trigger CRA, NIS2 and GDPR duties at once, on different clocks and to different recipients. The SRP covers the CRA leg. The others still need filing separately.

Going deeper

Each of these takes one part of the platform further.

Frequently asked

What is the SRP under the Cyber Resilience Act?
The Single Reporting Platform, or SRP, is the single entry point established under Article 16 of the Cyber Resilience Act to simplify manufacturers' reporting obligations. It is established by ENISA, and its day-to-day operations are managed and maintained by ENISA, with Member States and ENISA putting in place their own electronic notification end-points. A manufacturer submits through the end-point of its coordinating CSIRT, and under Article 14(7) that submission is simultaneously accessible to ENISA. The receiving CSIRT then disseminates it onward to the coordinating CSIRTs of the territories where the product was indicated as available. It carries the mandatory Article 14 cascade and the voluntary Article 15 channel, and is scheduled to be operational by 11 September 2026.
Who can report through the SRP?
Two different groups, depending on the channel. The mandatory channel is for manufacturers of products with digital elements, and for open-source software stewards where they are involved with such products. The voluntary channel is open to any natural or legal person, which includes security researchers, downstream integrators, customers and other vendors. Widening the voluntary funnel is deliberate, so that early or weaker signals from people who do not own the product still reach ENISA and the national CSIRTs.
What can you report voluntarily on the SRP?
Four categories, all broader than the mandatory triggers. Vulnerabilities contained in a product with digital elements, not only actively exploited ones. Cyber threats that could affect a product's risk profile. Incidents having an impact on a product's security that fall below the severe threshold. And near misses, meaning events that could have resulted in an incident but did not. The voluntary bar is deliberately lower than the mandatory bar.
When does the ENISA SRP go live?
The platform is scheduled to be operational by 11 September 2026, matching the date the Article 14 manufacturer reporting obligations enter application. The mandatory and voluntary functions do not arrive together. ENISA has indicated that the voluntary reporting functionality follows the mandatory channel rather than launching alongside it.
Does the ENISA SRP have an API for manufacturers?
Not at this stage. Article 14(7) routes notifications through the platform, but ENISA does not currently expose a submission API for manufacturers, so the filing itself remains a manual step. What can be automated is everything around it: starting the clocks on intake, driving triage, tracking the deadlines and assembling the submission package so that the manual step takes minutes rather than hours.
What information does the SRP ask for at 24 hours?
Very little, by design. The early warning needs the notification type and level, the manufacturer or steward name, the product, a title, and the Member States where the product is available if applicable. Product type and Annex category are optional at this stage. Timestamps and reporter identity are filled automatically. The 72-hour notification then asks for a real assessment, and the final report carries the full description and remediation detail.
Do you report to ENISA or to your national CSIRT?
Both, in one filing. Article 14(7) has the notification submitted through the electronic notification end-point of the CSIRT designated as coordinator of the Member State where your main establishment in the Union sits, and routed to ENISA at the same time. They are not alternatives and you do not choose between them. If you have no establishment in the Union, the routing follows the Member State of your authorised representative or importer.

Arrive at the SRP with the fields already filled

CVD Portal takes reports through a branded disclosure portal, starts the Article 14 timers the moment a case is flagged as exploited, drives triage, and assembles a submission-ready package in the shape the platform asks for. A human still files it, because the platform offers no other route.

Receiving and tracking reports is free. EU data residency by default, no card required to start.

CVD Portal supports CRA compliance work but does not provide legal advice and does not by itself establish conformity or a presumption of conformity. It is an independent platform, not affiliated with or endorsed by the EU or ENISA.