CRA Kit
Blog · · 3 min read · CRA · Cyber Resilience Act

What to have ready before you open ENISA's platform

The Single Reporting Platform went live on 11 September 2026. What Article 14 expects you to produce, with the article behind each piece.

ENISA announced the launch of the CRA Single Reporting Platform on 11 September 2026. Hogan Lovells Cadwalader published a note on the reporting duties and the platform today, 12 September 2026. Infosecurity Magazine, The Register and Raspberry Pi all covered the start of the 24-hour clock on 11 September 2026.

The channel exists now because Article 16 puts it there, and Article 14 is the duty that sends you to it.

I have not filed a report through the platform. I am not going to describe screens I have not used. What I can describe is the material Article 14 expects from you, because that part sits in the text and does not move with the interface.

Two situations send you there

Article 14(1) covers an actively exploited vulnerability contained in your product. Article 3(42) defines the term. Reliable evidence that a malicious actor has exploited the vulnerability in a system without the owner's authorisation.

Article 14(3) covers a severe incident having an impact on the security of the product. Article 14(5) gives the test. The incident affects or can affect the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions. Or it has led or can lead to malicious code being introduced into the product, or executed in a user's systems.

Read both before you decide you have nothing to file.

Two recipients, not one

Article 14(1) names the CSIRT designated as coordinator in your member state, and ENISA. The report goes to both.

That is worth writing on the same page as your on-call notes. Which CSIRT covers you follows from where you are established, and looking it up at 2 a.m. is the wrong moment.

Three deadlines from one moment

The early warning is due within 24 hours. The notification is due within 72 hours. Both run from the moment you become aware, under Article 14(2) and Article 14(4).

Then the final report. For a vulnerability, 14 days after a corrective or mitigating measure is available. For an incident, one month after the notification.

The starting point is knowledge, not correspondence. Nobody writes to you to start the clock.

A Saturday example

Take a developer who sells a desktop app under their own name. One person, no company, and Article 3(13) still calls them a manufacturer.

On a Saturday afternoon a customer forwards a support thread. Their IT provider found requests hitting the app's update endpoint from an address they do not recognise, and a log line showing a file written outside the install directory. The customer asks whether this is known.

That message is the moment. Reliable evidence, third-party system, no authorisation. Article 3(42) fits.

The developer now has until Sunday afternoon for the early warning, and until Tuesday for the notification. Neither document requires a fix. The early warning is short by design. What takes the time on a Saturday is finding out which CSIRT to contact, deciding who at ENISA receives what, and writing a first description of the product while a customer waits for an answer.

Deciding all of that in advance costs an hour on a quiet weekday.

Your users hear from you as well

Article 14(8) is the part people skip. After you become aware of an actively exploited vulnerability or a severe incident, you inform the affected users without undue delay. All users, where appropriate. You tell them about the vulnerability or the incident and, where needed, about the mitigating and corrective measures they can apply themselves. In a structured, machine-readable format where possible.

The regulation sets no template for that message. So the wording is yours, and drafting it in advance is allowed.

What still waits for December 2027

Article 69 is the clarifying one for products already on the market before 11 December 2027. Article 14 applies to them. The rest applies on substantial modification, and Recital 39 says security updates and bug fixes are not one.

Everything else arrives on 11 December 2027 under Article 71. The essential requirements of Annex I, including the SBOM covering at least the top-level dependencies under Annex I Part II point 1. The coordinated vulnerability disclosure policy and contact address under points 5 and 6. Technical documentation, the EU declaration of conformity, CE marking. Penalties under Article 64 apply from that date too.

Before any of this, one question decides whether it is yours at all. If you are unsure, the free scope test walks through it with the article references: https://crakit.eu/scope/

Not legal advice.

This is not legal advice.

LD
Louann Duclos

Built CRA Kit. Writes here about what the regulation asks of a small software company. All posts · RSS feed