On 11 September 2026, a significant part of the European Union’s Cyber Resilience Act (CRA) entered its operational phase. With the entry into application of the EU ‘s CRA Article 14 on mandatory reporting obligations, manufacturers of products with digital elements made available on the EU market, including products already on the market, must now report actively exploited vulnerabilities and severe incidents affecting the security of their products. An early warning must be submitted within 24 hours of becoming aware of an actively exploited vulnerability or severe incident, followed by a more detailed notification within 72 hours. Final reporting obligations subsequently apply depending on the type of event.
At the same time, ENISA launched the CRA Single Reporting Platform (SRP) as the central mechanism through which manufacturers submit notifications. The SRP is intended to improve EU-wide vulnerability intelligence and coordination. ENISA will operate the platform, while notifications are received by the designated CSIRT and shared with other relevant CSIRTs. Information from manufacturer reporting can also contribute to Europe’s broader vulnerability-management ecosystem, including the EU Known Exploited Vulnerabilities (EU KEV) Catalogue. The potential strategic benefit is therefore considerable: incidents discovered by individual manufacturers can become intelligence available to a wider European defensive community.
by Digital Watch Observatory – EU Cyber Resilience Act: the first reporting phase exposes operational and technical challenges



