EU Cyber Resilience Act: Single Reporting Platform Goes Live
September 10, 2026
EU Cyber Resilience Act: Single Reporting Platform Goes LiveSeptember 10, 2026 From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through ENISA’s Single Reporting Platform within 24 hours. Internal reporting workflows and platform access credentials should be in place now. Why should I read this?The EU Cyber Resilience Act (CRA) reporting regime goes live on 11 September 2026. From that date, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through the Single Reporting Platform (SRP), operated by the EU Agency for Cybersecurity (ENISA). One submission reaches the relevant national cybersecurity authorities across the EU. The clock is short: an early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report within 14 days of a fix for vulnerabilities or within one month for incidents. Registering on the platform takes minutes and is only needed when a report is due; what takes time is the internal workflow to detect, decide and file within 24 hours. Full application of the CRA, including penalties, follows on 11 December 2027. What should I do?Manufacturers should act now on platform access, internal process design and reporting-scope review.
What else do I need to know about the CRA Single Reporting Platform?One submission, cross-border reachThe manufacturer submits one notification through the SRP, addressed simultaneously to the CSIRT designated as coordinator and to ENISA. The coordinating CSIRT disseminates without delay to CSIRTs in Member States where the product is available. Delegated Regulation (EU) 2026/881, adopted in December 2025, permits delayed dissemination where justified on cybersecurity grounds. This includes cases where the security of the SRP itself has been compromised. Parallel obligations under NIS2 and DORA do not go awayThe CRA is product-focused; NIS2, the EU directive on cybersecurity of essential and important entities, is entity-focused. Both use a 24-hour/72-hour structure, but the obligations run in parallel. Once a corrective measure is available, ENISA adds the reported vulnerability to the European vulnerability database established under NIS2. DORA, the Digital Operational Resilience Act, applies to financial entities and their information and communication technology (ICT) third-party risk; CRA obligations do not displace DORA incident reporting. Organisations under both regimes should map the overlaps now. What comes next: Conformity assessment, standards and penaltiesFull CRA application follows on 11 December 2027, when the essential cybersecurity requirements, conformity assessment, market surveillance and penalties take effect. Fines are set by each Member State within EU ceilings of up to EUR 15 million or 2.5% of worldwide turnover, and imposed by national market surveillance authorities. Micro and small enterprises cannot be fined for missing the 24-hour deadline. The harmonised standards that will give manufacturers a presumption of conformity are still being developed. The Commission’s guidance of 27 July 2026 explains the reporting obligations in practice and is worth reading alongside ENISA’s platform guidance. Open-source software stewards will also be subject to reporting obligations from 11 December 2027, to the extent they are involved in developing the products. Voluntary reporting through the SRP will follow in a later phase. Further reading on the CRA Single Reporting Platform
Latest Insights
Latest News
Latest Events
legal updates September 10, 2026 Global Life Sciences & Healthcare Bulletin legal updates September 10, 2026 Hong Kong: PCPD issues further guidance on best practices in the use of age... guides and reports September 10, 2026 EU Cyber Resilience Act: Single Reporting Platform Goes Live legal updates September 09, 2026 EU Sustainability Omnibus Package: key changes and implications for busines... firm news August 26, 2026 Eversheds Sutherland strengthens top-ranked pensions practice with appointm... client news August 13, 2026 Eversheds Sutherland advises H.I.G. Capital on investment in Phoenix ME client news August 13, 2026 Eversheds Sutherland reappointed to the UK's Government Commercial Agency l... firm news August 12, 2026 William A. Nelson, Former Investment Adviser Association Policy Leader, Joi... in-person Basic foundations of US employment law September 17, 2026 9.30am - 4.30pm (GMT) London, United Kingdom in-person 2026 BDC Roundtable September 23, 2026 Washington DC, United States virtual Employment law in the Kingdom of Saudi Arabia September 29, 2026 9.30am - 12.30pm (BST) Virtual in-person Labor relations conference - turning legal change into workplace reality October 08, 2026 10.00am - 4.00pm (BST) London, United Kingdom |