← CRA FAQReporting and vulnerability handling

Which CSIRT do I report to under the CRA, and how does the ENISA single reporting platform work?

Also asked

  • Do I notify every Member State CSIRT separately under the CRA?
  • How do I work out my main establishment for CRA reporting?
  • What do I file at 24 hours, 72 hours and 14 days?
  • Can I ask for my CRA notification to be kept from other Member States?
  • Does a manufacturer outside the EU report through the single reporting platform?

Article 14(7) of the Cyber Resilience Act routes every notification to the CSIRT designated as coordinator in the Member State where the manufacturer has its main establishment in the Union, meaning where decisions about the cybersecurity of its products are predominantly taken. A manufacturer with no establishment in the Union follows a four-step fallback based on authorised representative, importer, distributor, then users. One submission through the ENISA single reporting platform reaches that CSIRT and ENISA simultaneously, and the deadlines run from 11 September 2026.

The determination is made once and recorded, because the 24-hour clock leaves no room to work out the routing after a vulnerability is already being exploited.

At a glance

Primary rule
CSIRT of the Member State of main establishment (Article 14(7))
Main establishment test
Where product cybersecurity decisions are predominantly taken
Tie-break
Establishment with the highest number of EU employees
No EU establishment
Authorised representative, importer, distributor, then users
Recipients
Coordinating CSIRT and ENISA, simultaneously, in one submission
Applies from
11 September 2026, including for products already on the market

Last reviewed 27 July 2026

Verified against The final text of Regulation (EU) 2024/2847 as published in OJ L, 20.11.2024, read at EUR-Lex on 27 July 2026

The single reporting platform was not live as at 27 July 2026 and is scheduled to be operational by 11 September 2026. Operational detail, including end-point registration, validation and submission formats, is still being published by ENISA and the national CSIRTs, so the readiness section dates faster than the legal analysis.

Which CSIRT is yours, exactly?

Article 14(1) and (3) require a manufacturer to notify an actively exploited vulnerability, and a severe incident having an impact on the security of the product, simultaneously to the CSIRT designated as coordinator and to ENISA, through the single reporting platform.[1]

Article 14(7) decides which CSIRT that is. The notification goes to the electronic notification end-point of the CSIRT designated as coordinator of the Member State where the manufacturer has its main establishment in the Union, and is simultaneously accessible to ENISA.[1]

Main establishment has a specific meaning here. It is the Member State where the decisions related to the cybersecurity of the manufacturer's products with digital elements are predominantly taken. Where that Member State cannot be determined, it is the Member State in which the manufacturer has the establishment with the highest number of employees in the Union.[1]

Note what the test is not. It does not follow the registered office, the group headquarters, the place of incorporation or the largest market. It follows where product security decisions actually get made, which for many groups is an engineering site rather than a corporate seat.

A manufacturer with no main establishment in the Union works down a strict order, based on the information available to it:

  1. The Member State where the authorised representative acting for the highest number of that manufacturer's products is established.
  2. The Member State where the importer placing the highest number of those products on the market is established.
  3. The Member State where the distributor making the highest number of those products available is established.
  4. The Member State where the highest number of users of those products are located.

There is a stability provision attached to the fourth limb. Where a manufacturer reaches step 4, it may submit notifications about any subsequent actively exploited vulnerability or severe incident to the same coordinating CSIRT it first reported to, rather than recalculating user distribution each time.[1]

CRA referenceArticle 14(1), (3) and (7)

What the single reporting platform actually does

Article 16(1) requires ENISA to establish the single reporting platform for the notifications under Article 14(1) and (3) and Article 15(1) and (2), expressly in order to simplify manufacturers' reporting obligations. ENISA manages and maintains its day-to-day operations, and its architecture allows Member States and ENISA to put in place their own electronic notification end-points.[3]

The practical consequence is the one manufacturers most often get wrong. You file once, at your coordinating CSIRT's end-point, and that single submission is simultaneously accessible to ENISA. There is no separate ENISA filing, and no obligation to notify each Member State where the product is sold.

Distribution is handled for you. Under Article 16(2), the coordinating CSIRT that initially receives the notification must without delay disseminate it via the platform to the coordinating CSIRTs of the Member States where the manufacturer has indicated the product has been made available.[3]

That indication is your job, and it is made at the first step. Article 14(2), point (a), requires the 24-hour early warning to indicate, where applicable, the Member States on whose territory the manufacturer is aware the product has been made available.[1] Getting that list wrong at hour 24 is what narrows or misdirects the dissemination that follows.

The Article 16 explainer covers the platform architecture, the European Vulnerability Database and ENISA's wider coordination role.

CRA referenceArticle 16(1) and (2), Article 14(2)(a)

What you file, and when

Two tracks run on the same clock shape and diverge at the final report. Both start when the manufacturer becomes aware.

For an actively exploited vulnerability, under Article 14(2):[1]

  1. Early warning, without undue delay and in any event within 24 hours, indicating where applicable the Member States where the product has been made available.
  2. Vulnerability notification, within 72 hours, giving general information about the product, the general nature of the exploit and of the vulnerability, corrective or mitigating measures taken, and measures users can take. This is also where the manufacturer indicates how sensitive it considers the information to be.
  3. Final report, no later than 14 days after a corrective or mitigating measure is available, describing the vulnerability including severity and impact, any information on the malicious actor exploiting it, and details of the security update or other corrective measures.

For a severe incident, under Article 14(4):[1]

  1. Early warning within 24 hours, including at least whether the incident is suspected of being caused by unlawful or malicious acts.
  2. Incident notification within 72 hours, with the nature of the incident, an initial assessment, and corrective or mitigating measures.
  3. Final report within one month after the submission of the incident notification, with a detailed description including severity and impact, the type of threat or likely root cause, and applied and ongoing mitigation measures.

The two final-report clocks are the most commonly swapped pair in this Regulation. A vulnerability final report runs 14 days from a fix being available. An incident final report runs one month from the 72-hour notification, so it is anchored to a filing rather than to a remedy.

CRA referenceArticle 14(2) and (4)

The obligation that is not a filing

Article 14(8) sits alongside the notifications and is easy to miss because it points at customers rather than authorities.

After becoming aware of an actively exploited vulnerability or a severe incident, the manufacturer has to inform the impacted users of the product, and where appropriate all users, of that vulnerability or incident, and where necessary of any risk mitigation and corrective measures users can deploy. Where appropriate this should be in a structured, machine-readable format that is easily automatically processable.[1]

That last clause is the practical argument for producing a CSAF advisory rather than a prose security bulletin, since CSAF is the machine-readable advisory format the ecosystem has settled on.[8]

There is an enforcement tail. Where the manufacturer fails to inform users in a timely manner, the notified coordinating CSIRTs may provide that information to users themselves, where considered proportionate and necessary to prevent or mitigate impact.[1] Losing control of your own disclosure to a national CSIRT is a reputational outcome worth engineering against.

CRA referenceArticle 14(8)

Can you stop your report reaching every Member State?

Partly, and the decision is never yours.

Article 16(2) allows dissemination of a notification to be delayed on justified cybersecurity-related grounds for a period that is strictly necessary, in exceptional circumstances and in particular on the manufacturer's request, taking into account the sensitivity the manufacturer indicated under Article 14(2), point (a). It names an ongoing coordinated vulnerability disclosure procedure under Article 12(1) of Directive (EU) 2022/2555 as an example. A CSIRT that withholds a notification must immediately inform ENISA of the decision, the justification and when it intends to disseminate.[3]

In particularly exceptional circumstances the restriction goes further, where the manufacturer indicates that the vulnerability has been actively exploited and, on available information, in no Member State other than that of the receiving CSIRT, and that immediate further dissemination would carry the risks the provision sets out.[3]

Commission Delegated Regulation (EU) 2026/881, adopted under Article 14(9) on 11 December 2025 and published in the Official Journal on 20 April 2026, specifies the terms and conditions for applying those cybersecurity-related grounds.[6]

Two points of realism. The receiving CSIRT decides, and it is permitted to delay rather than obliged to. And the mechanism affects dissemination between CSIRTs, so it does nothing to the 24-hour and 72-hour deadlines that apply to you.

CRA referenceArticle 16(2), Article 14(9)

From when, and does it reach products already sold?

Article 71(2) applies Article 14 from 11 September 2026, more than a year before the rest of the Regulation applies on 11 December 2027.[5]

The part that catches people out is the legacy portfolio. Article 69(2) generally exempts products placed on the market before 11 December 2027 from the Regulation unless they undergo a substantial modification. Article 69(3) then derogates from that specifically for Article 14, so the reporting obligations apply to all products within scope that were placed on the market before that date.[4]

So the exposure on an existing product line is the reverse of the common assumption. The Article 13 design and risk assessment duties generally do not reach it. The Article 14 reporting duties do, and they start first.

Voluntary reporting is available on the same platform. Article 15 lets manufacturers, and other natural or legal persons, voluntarily notify vulnerabilities, cyber threats and incidents that fall outside the mandatory triggers.[2]

CRA referenceArticle 71(2), Article 69(2) and (3), Article 15

Is the platform live, and what should you do before September 2026?

Not yet. ENISA states that the platform is scheduled to be operational by 11 September 2026, the date the mandatory reporting obligations enter into application, with a testing period before then.[9][10]

That leaves no slack. The platform becomes available on the same day the 24-hour clock starts running, so there is no grace period in which to discover how it works.

Two pieces of onboarding can be done ahead of launch, and one of them has a lead time outside your control.

  • Create an EU Login account in advance. ENISA directs manufacturers to register at the Commission's authentication service before using the platform.[9][11]
  • Expect validation to run in parallel rather than in advance. ENISA indicates that the designated coordinating CSIRT validates a manufacturer's representatives after first access to the platform, alongside the reporting process rather than as a prerequisite completed beforehand.[9]

The work that genuinely cannot wait is the determination in the first section. Establish which CSIRT is yours under Article 14(7), write down the reasoning, and keep the record with your technical documentation. That question has a defensible answer today, and answering it during an active exploitation is how a 24-hour deadline gets missed.

ENISA maintains a dedicated FAQ for the platform, updated as implementation proceeds. Treat it as the operational source and this answer as the legal one.[9]

CRA referenceArticle 14(7), Article 16(1)

Sources

Every claim above traces to one of these. Items marked Binding are law in force. Everything else is interpretive and is labelled as such.

  1. [1]

    Publications Office of the European Union · Article 14(1) to (9) · CELEX:32024R2847 · OJ L, 20.11.2024

    the Member State where the decisions related to the cybersecurity of its products with digital elements are predominantly taken

    Accessed 2026-07-27

  2. [2]

    Publications Office of the European Union · Article 15(1) and (2) · CELEX:32024R2847

    Accessed 2026-07-27

  3. [3]

    Publications Office of the European Union · Article 16(1) and (2) · CELEX:32024R2847

    a single reporting platform shall be established by ENISA. The day-to-day operations of that single reporting platform shall be managed and maintained by ENISA

    Accessed 2026-07-27

  4. [4]

    Publications Office of the European Union · Article 69(2) and (3) · CELEX:32024R2847

    the obligations laid down in Article 14 shall apply to all products with digital elements that fall within the scope of this Regulation

    Accessed 2026-07-27

  5. [5]

    Publications Office of the European Union · Article 71(2) · CELEX:32024R2847

    Article 14 shall apply from 11 September 2026

    Accessed 2026-07-27

  6. [6]

    Publications Office of the European Union · Adopted under Article 14(9) CRA · Delegated Regulation (EU) 2026/881 · Published in the Official Journal on 20 April 2026

    Accessed 2026-07-27

  7. [7]

    Publications Office of the European Union · Article 12(1) · CELEX:32022L2555

    Accessed 2026-07-27

  8. [8]

    OASIS Open · OASIS Standard, CSAF 2.0

    An industry standard for machine-readable advisories. The CRA requires a structured, machine-readable format where appropriate without naming CSAF.

    Accessed 2026-07-27

  9. [9]

    European Union Agency for Cybersecurity (ENISA) · Platform status, onboarding and EU Login registration · FAQ updated 17 July 2026

    Agency material describing implementation. It records how the platform is being built and creates no obligations of its own. ENISA states the FAQ is updated as implementation proceeds.

    Accessed 2026-07-27

  10. [10]

    European Commission, DG CONNECT · Single reporting platform readiness and reporting deadlines · As published, July 2026

    A Commission policy page describing implementation progress. It creates no obligations beyond the Regulation.

    Accessed 2026-07-27

  11. [11]

    European Commission · Account registration required before using the platform

    An access mechanism rather than a legal instrument. ENISA directs manufacturers to register here ahead of platform launch.

    Accessed 2026-07-27

Follow-up questions

Do I have to notify ENISA separately from my CSIRT?+

No. Article 14(1) requires simultaneous notification to the coordinating CSIRT and ENISA, and Article 14(7) achieves it through one submission at the CSIRT's electronic notification end-point on the single reporting platform, which is simultaneously accessible to ENISA. A second, separate filing to ENISA is not required.

Our registered office and our engineering site are in different Member States. Which one governs?+

Neither automatically. Article 14(7) asks where the decisions related to the cybersecurity of your products are predominantly taken, which usually points at the engineering or product security function rather than the corporate seat. Only if that cannot be determined does the test fall back to the establishment with the highest number of employees in the Union.

Who actually files, the manufacturer or the importer?+

The manufacturer, or an authorised representative acting for it. Importers and distributors do not file Article 14 notifications. They carry their own duties, including informing the manufacturer about vulnerabilities they become aware of in a product they have placed or made available on the market.

Does an unexploited vulnerability trigger the 24-hour clock?+

No. Article 14(1) is triggered by an actively exploited vulnerability, and Article 14(3) by a severe incident having an impact on the security of the product. A vulnerability you discover and fix with no evidence of exploitation falls outside the mandatory triggers, though Article 15 voluntary reporting remains available.

What counts as a severe incident?+

Article 14(5) sets the test. An incident is severe where it negatively affects or is capable of negatively affecting the ability of the product to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or where it has led or is capable of leading to the introduction or execution of malicious code in the product or in the network and information systems of a user of the product.

Work out where your product actually lands

Free CRA classification for your product, a vulnerability disclosure portal on your own domain, and Article 14 deadline tracking. Receiving and tracking reports is free for every manufacturer placing products with digital elements on the EU market.