The CRA Single Reporting Platform Is Live: How to Register Before You Need It
Reporting obligations under Article 14 of the Cyber Resilience Act became mandatory on 11 September 2026. Until that same day, the tool you were supposed to report through did not exist for public use. ENISA's CRA Single Reporting Platform (SRP) went live at portal.cra-srp.enisa.europa.eu on 11 September 2026, with access instructions, user manuals and terms of service published the day before. If your organisation hasn't registered yet, the clock on your first actively exploited vulnerability or severe incident won't wait for you to figure out the portal.
What the SRP is for
The SRP is the single channel for the notifications Article 14 requires: an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident, a fuller notification with an initial assessment within 72 hours, and a final report within 14 days of a corrective or mitigating measure becoming available. The clock starts when the manufacturer becomes aware of the event, not when the platform is convenient.
In this first release, the SRP is a web interface only - no API yet - and it operates in English, with other languages planned later.
Who registers, and as what
Access runs through EU Login with multi-factor authentication enabled. Each manufacturer (or open-source steward) needs at least one Primary Assigned Representative (AR) and can add up to 20 Secondary ARs.
Primary AR registration is a direct, self-service process:
- Authenticate through EU Login (MFA required).
- Select your CSIRT Designated as Coordinator (CDaC) - in practice, the national CSIRT tied to your primary EU establishment.
- Accept the platform's legal terms.
- Confirm your personal details and enter your manufacturer information.
- Your account becomes Active with the AR Primary User role.
Secondary AR registration starts with an email invitation from a verified Primary AR. The invited person authenticates via EU Login, confirms their pre-filled details, and accepts the manufacturer association - but that invitation link expires after seven days, so it needs to be actioned promptly rather than left in an inbox.
One detail worth flagging to whoever owns this internally: association validation by the designated CSIRT happens after registration, not before. A pending AR can already begin working in the system - which is one more reason not to leave this until the middle of an actual incident.
Choosing your CSIRT coordinator matters
The CSIRT you select as your CDaC becomes the entity that receives your notifications and forwards them to other Member States affected by the same vulnerability or incident. For most manufacturers this is a straightforward lookup based on where their primary EU establishment sits - but multinationals with several EU entities should decide this deliberately, once, rather than have it decided by whoever happens to be registering that day.
Building the process behind the login
Registration is the easy part. What the platform doesn't do for you is the harder work: standing up an internal detection and triage process that can actually recognise an actively exploited vulnerability or a severe incident when it happens, and route it to whoever holds the Primary or Secondary AR role fast enough to hit the 24-hour early warning. If you haven't already read it, our PSIRT explainer covers who inside your organisation should own that function.
What to do this week
- Confirm who in your organisation will hold the Primary AR role, and register them.
- Add Secondary ARs for backup coverage - a single point of failure on a 24-hour clock is a bad idea.
- Identify your CDaC now, before an incident forces a rushed decision.
- Run a dry registration and, if your process allows it, a test notification, so the first time your team touches the SRP isn't during a live incident.
The reporting deadline was fixed months in advance. The platform arrived on the day it was due. The gap left for most manufacturers is operational readiness, not legal uncertainty - and that gap closes fastest by registering now rather than after the next actively exploited CVE lands on your desk.
Related reading
Three Weeks Into CRA Reporting: What Early Users Learned and What a "Disclosure Delay" Really Means
Article 14 reporting has been live for three weeks. Here is what early users of ENISA's Single Reporting Platform report, what a "disclosure delay" does and does not change, and the four things worth doing this week.
CRA SBOM Requirements: What Goes Inside, Which Format Versions to Use, and Where VEX Fits
The CRA says your SBOM must be machine-readable but not what fields it needs. Here is what goes inside, which CycloneDX and SPDX versions still count, and why VEX is optional.

Does the Cyber Resilience Act Require Penetration Testing?
The CRA never mentions penetration testing. Annex I, Part II, point 3 requires "effective and regular" security tests - here is what that means in practice.