← Back to CRA Insights
News and updates

EU Cyber Resilience Act News Today: Where Every Open Workstream Stands, Three Days Before Reporting Switches On

Generated image

Three days from now - on 11 September 2026 - the EU Cyber Resilience Act's Article 14 reporting obligations switch on. The core rule is settled and has been for months. What is still moving are the surrounding pieces: the platform you file through, the standards that would give you a presumption of conformity, and a legislative proposal that some have mistakenly read as a reason to wait. This post maps exactly where each workstream stands today, 8 September 2026.

TL;DR - key points

  • 11 September 2026 is fixed. Article 14 reporting applies from that date. It covers products already on the EU market, not just new launches.
  • The ENISA Single Reporting Platform (SRP) is scheduled to go live the same day it becomes mandatory. As of this writing, its public URL has not been published. Have an offline record of the facts you would need to file.
  • ENISA published the list of coordinating CSIRTs for all 27 Member States on 4 September 2026. That gap is now closed.
  • 17 ETSI draft standards are in Public Enquiry. None is a harmonised standard yet. None confers a presumption of conformity under Article 27.
  • The Digital Omnibus Single Entry Point is a proposal in the legislative process. It changes nothing about 11 September 2026.

This article is general guidance on the Cyber Resilience Act, not legal advice. Confirm specifics against Regulation (EU) 2024/2847 and official ENISA and Commission sources. Our reporting may be overtaken by events - check the ENISA SRP page for the latest.


What actually changes on 11 September 2026

From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform. The obligation flows from Article 14 of[1] Regulation (EU) 2024/2847.

The timelines are:

  • 24 hours from awareness of an actively exploited vulnerability - early warning to your coordinating CSIRT and ENISA via the SRP.
  • 72 hours from awareness - fuller notification with more detail.
  • 14 days after a corrective measure is available - final report for an actively exploited vulnerability.
  • One month from the 72-hour notification - final report for a severe incident.

Two things about scope that still catch people out.

First, the reporting obligation covers products already placed on the EU market before full application in December 2027 - it is not limited to new products. If you shipped a connected device or software product into the EU last year, Article 14 applies to it from Thursday.

Second, the obligation does not reach back. If you were already aware of an actively exploited vulnerability before 11 September 2026, the clock does not start retroactively. It starts when you become aware of a new exploitation after that date.

For a full explanation of what triggers a report and what does not, see our Article 14 trigger guide and the 11 September reporting deadline explainer.


The reporting platform: what ENISA has said, and what is still unclear

This is the area of greatest operational uncertainty right now, so it is worth being precise about what is confirmed and what is not.

What is confirmed:

The Single Reporting Platform will be operational by 11 September 2026, the date of entry into application of the CRA reporting requirements.[2] Pursuant to Article 16 of the CRA, ENISA is tasked with establishing the SRP, and has procured services from a contractor to assist with its development.

At launch, the platform will support only mandatory reporting of actively exploited vulnerabilities and severe incidents under Article 14. Voluntary reporting under Article 15 will not be available at launch and will be introduced in a future phase of the platform.

On 4 September 2026, exactly one week before reporting starts, ENISA published the list of CSIRTs designated as coordinators, alongside a near-total rewrite of the Single Reporting Platform FAQ. That list had been the most-cited outstanding gap in reporting readiness. It is now resolved.

ENISA has confirmed that the person who registers and files for a manufacturer or an open-source software steward does so with an EU Login account, which can be created in advance. ENISA published a factsheet and step-by-step guidance in July 2026. There are now three guides: registration and notification submission, both updated 3 August 2026, and platform interface functions, updated 14 August 2026.

What is still unclear:

The Single Reporting Platform is not yet live. Its public URL has still not been published; ENISA says it will appear on the SRP page before the platform goes live.

The SRP will not offer an API at launch. The ENISA SRP FAQ confirms that all mandatory reports must be filed through the web portal, not through an automated submission pipeline. This means that even manufacturers with fully automated SBOM-to-vulnerability monitoring must terminate their automated workflow at the portal boundary and submit manually.

For a deeper look at how reports flow through the platform, see our ENISA Single Reporting Platform deep-dive.


Standards: 17 ETSI drafts in public enquiry, none citable yet

The standards workstream is moving, but it is on a separate clock from reporting - and it is important not to conflate the two.

On 13 August 2026, ETSI put 17 final draft CRA product standards under Public Enquiry.[3] They cover connected products with digital elements exposed to a higher risk of compromise, such as password managers, anti-virus software, smart home assistants, connected toys, and wearables.

These standards aim to become harmonised standards, giving manufacturers a recognised way to demonstrate compliance - the so-called "presumption of conformity". The ETSI EN 304 series standards on cybersecurity requirements were submitted this summer to member organisations across Europe, including the national standardisation bodies of the European Economic Area.

The critical point: No CRA harmonised standard has yet been cited in the Official Journal of the EU. None of these documents is a harmonised standard, so none of them currently confers the presumption of conformity under Article 27. They are final drafts in the first phase of approval, and the wording will change.

Stakeholders can comment until mid-September to mid-November 2026, depending on the vertical. The final versions of these 17 standards are expected to be available by December 2026.

Even when the final versions are published in December, citation in the Official Journal - the step that actually triggers the Article 27 presumption - will follow later still. Until that citation happens, the ETSI drafts are useful technical references, but they do not give you a legal shortcut.

For a full breakdown of what each of the 17 drafts requires by product category, see our harmonised standards post and the ETSI 17 standards post.


The Digital Omnibus: a proposal, not a reprieve

The Commission's Digital Omnibus package has generated a lot of commentary. Some of it has been read - incorrectly - as suggesting that CRA reporting obligations might be absorbed into a future unified system before they apply. They will not be.

The EU Digital Omnibus is a legislative package introduced by the European Commission on 19 November 2025, aimed at simplifying Europe's growing stack of digital regulations. The Digital Omnibus proposes the implementation of a Single-Entry Point (SEP) mechanism for cybersecurity incident reporting.[4] The SEP would take the form of a centralised, fully digital reporting platform managed by ENISA.

The data part of the Digital Omnibus, under which NIS2 and cybersecurity is addressed, is still in negotiation. The European Parliament expects the SEP to become operational within 18 months of the package entering into force, with a possible extension to two years if additional time is needed.

The practical consequence is straightforward: the SEP does not exist yet, it is not law yet, and even after it becomes law it will take 18-24 months to build. The Digital Omnibus Single Entry Point changes nothing about the 11 September 2026 reporting obligation. Existing mechanisms - including the CRA SRP - stay in place until the SEP is operational.

The proposal also envisages that a single incident report would satisfy notification requirements under the GDPR, NIS2 and DORA. That is a future aspiration, not a current reality.


What is still unfinished

Beyond the SRP URL, three other workstreams remain open as of 8 September 2026.

1. Harmonised standards citation in the Official Journal

As noted above, no CRA harmonised standard has been cited in the OJEU[5]. No common specifications have been adopted for the CRA. No delegated act designates any European cybersecurity certification scheme as a CRA presumption-of-conformity route. This affects conformity assessment routes, not the reporting obligation.

2. Delegated acts

The Commission has adopted a delegated act specifying the conditions under which a CSIRT may delay dissemination of a notification. The Commission may still specify the format and procedure for notifications further through implementing acts. Those implementing acts have not yet been published.

3. Notification format

ENISA's FAQ sets out which data fields are obligatory at the 24-hour, 72-hour and final-report stages, so you can build a matching internal template today. The Commission retains the power to specify format further, but the fields ENISA has published are the working baseline.


What to do this week

The following actions do not require the SRP to be live. They can be completed today.


Where to go next on CRA Facts

The posts below cover the ground this roundup deliberately does not re-tread.