← CRA FAQReporting and vulnerability handling

Do I have to use the ENISA single reporting platform to report under the CRA?

Also asked

  • How is my main establishment determined under the CRA?
  • What happens to a notification after I submit it?
  • Can a CSIRT delay passing on my notification?
  • Does someone else reporting my vulnerability count as my notification?

Article 14(7) leaves no alternative channel for mandatory notifications. Early warnings and the notifications that follow are submitted via the single reporting platform established under Article 16, using the electronic notification end-point of the CSIRT designated as coordinator of the Member State where you have your main establishment in the Union, and the submission is simultaneously accessible to ENISA. Voluntary reports under Article 15 are different, going to a coordinating CSIRT or ENISA and processed through the same Article 16 procedure. The platform is due to be operational on 11 September 2026.

The platform serves both the mandatory and voluntary channels, so a single filing route covers reporting duties and discretionary disclosures alike.

At a glance

Mandatory route
Single reporting platform, Article 14(7)
Which end-point
Coordinating CSIRT of your main establishment in the Union
ENISA
Notification simultaneously accessible to ENISA
Main establishment
Where product cybersecurity decisions are predominantly taken
Platform operator
Established, managed and maintained by ENISA, Article 16(1)
Applies from
11 September 2026

Last reviewed 7 August 2026

Verified against Regulation (EU) 2024/2847 Articles 14(7), 15 and 16 as published in OJ L, 20.11.2024, read in full text on EUR-Lex on 7 August 2026.

The platform is not yet in operation. End-point architecture, submission mechanics and any future API are implementation decisions taken by ENISA and the Member States under Article 16(1), and practice will sharpen once filings begin in September 2026.

For mandatory notifications there is one route

Article 14(7) states that the notifications referred to in Article 14(1) and (3) shall be submitted via the single reporting platform referred to in Article 16, using one of the electronic notification end-points referred to in Article 16(1).[1] There is no parallel channel, no direct-to-ENISA alternative, and no national form that substitutes for it.

Which end-point you use is determined rather than chosen. The notification is submitted using the end-point of the CSIRT designated as coordinator of the Member State where the manufacturer has its main establishment in the Union, and it is simultaneously accessible to ENISA.[1] ENISA and the coordinating CSIRT are not alternatives you pick between.

Article 16(1) puts the platform itself in ENISA's hands. It is established by ENISA, its day-to-day operations are managed and maintained by ENISA, and its architecture allows Member States and ENISA to put in place their own electronic notification end-points.[3]

CRA referenceArticle 14(7) and Article 16(1)

How your Member State is worked out

Article 14(7) defines main establishment for this purpose as the Member State where the decisions related to the cybersecurity of the manufacturer's products with digital elements are predominantly taken. Where that Member State cannot be determined, it is the Member State where the manufacturer has the establishment with the highest number of employees in the Union.[1]

A manufacturer with no main establishment in the Union follows an ordered cascade, based on the information available to it: the Member State of the authorised representative acting for the highest number of its products, then the Member State of the importer placing the highest number on the market, then the Member State of the distributor making the highest number available, then the Member State with the highest number of users.[1]

This is a determination to settle before an incident rather than during one. Working out which CSIRT is your coordinator while a 24-hour clock runs is avoidable work.

CRA referenceArticle 14(7), second and third subparagraphs

What the platform does with your notification

Article 16(2) puts dissemination on the receiving CSIRT. After receiving a notification, the coordinating CSIRT initially receiving it shall without delay disseminate it via the platform to the coordinating CSIRTs of the territories where the manufacturer has indicated the product has been made available.[3]

That dissemination can be held back. In exceptional circumstances, particularly on the manufacturer's request and in light of the sensitivity indicated under Article 14(2), point (a), dissemination may be delayed on justified cybersecurity-related grounds for a strictly necessary period, including where the vulnerability is subject to a coordinated vulnerability disclosure procedure under Article 12(1) of the NIS2 Directive. A CSIRT that withholds must immediately inform ENISA, give its justification, and indicate when it will disseminate.[3][4]

The practical consequence is that the sensitivity flag on your 24-hour filing is a real lever rather than a formality. It is the input that the withholding decision is made against.

CRA referenceArticle 16(2)

The voluntary channel works differently

Article 15 opens a second channel with a much wider entrance. Manufacturers as well as other natural or legal persons may voluntarily notify any vulnerability contained in a product with digital elements and any cyber threat that could affect its risk profile, and separately any incident having an impact on the security of the product and any near miss that could have resulted in such an incident.[2]

Those notifications go to a CSIRT designated as coordinator or ENISA, and are processed in accordance with the Article 16 procedure. The coordinating CSIRT may prioritise mandatory notifications over voluntary ones.[2]

Two consequences matter to a manufacturer. Where someone other than the manufacturer voluntarily notifies an actively exploited vulnerability or a severe incident in your product, the coordinating CSIRT shall without undue delay inform you.[2] And voluntary reporting shall not result in the imposition of additional obligations on the notifier, which removes a common reason for hesitating over a borderline case.[2]

CRA referenceArticle 15(1) to (5)

Sources

Every claim above traces to one of these. Items marked Binding are law in force. Everything else is interpretive and is labelled as such.

  1. [1]

    Publications Office of the European Union · Article 14(7) · CELEX:32024R2847 · OJ L, 20.11.2024

    shall be submitted using the electronic notification end-point of the CSIRT designated as coordinator of the Member State where the manufacturers have their main establishment

    Accessed 2026-08-07

  2. [2]

    Publications Office of the European Union · Article 15(1) to (5) · CELEX:32024R2847 · OJ L, 20.11.2024

    near misses that could have resulted in such an incident on a voluntary basis to a CSIRT designated as coordinator or ENISA

    Accessed 2026-08-07

  3. [3]

    Publications Office of the European Union · Article 16(1) and (2) · CELEX:32024R2847 · OJ L, 20.11.2024

    a single reporting platform shall be established by ENISA

    Accessed 2026-08-07

  4. [4]

    Publications Office of the European Union · Article 12(1) · CELEX:32022L2555

    Accessed 2026-08-07

  5. [5]

    European Union Agency for Cybersecurity (ENISA)

    Agency material describing implementation. It does not alter the obligations set by the Regulation.

    Accessed 2026-08-07

Follow-up questions

Can we submit through an API instead of the interface?+

Not at this stage. Article 14(7) routes notifications through the platform and Article 16(1) leaves the end-point architecture to ENISA and the Member States, but no manufacturer submission API is currently offered. The filing is a manual step for everyone. What can be prepared in advance is the content, so the manual step is a review and a submit rather than a drafting exercise against the clock.

A researcher already reported it voluntarily. Does that discharge our duty?+

No. Article 15(4) has the coordinating CSIRT inform the manufacturer without undue delay where another person notifies an actively exploited vulnerability or a severe incident, which means you may learn of your own obligation this way. Your Article 14 duty is your own, and being told about the report is likely to be the moment you become aware for the purposes of the clock.

Does the voluntary channel exist from day one?+

The platform is scheduled to be operational for 11 September 2026, when the Article 14 obligations enter application. ENISA has indicated the voluntary reporting functionality follows rather than arriving alongside the mandatory channel, so plan the mandatory route first and treat the voluntary one as a capability that becomes available later.

Work out where your product actually lands

Free CRA classification for your product, a vulnerability disclosure portal on your own domain, and Article 14 deadline tracking. Receiving and tracking reports is free for every manufacturer placing products with digital elements on the EU market.