EU Cyber Resilience Act: Single Reporting Platform Goes Live
2026 m. rugsėjo 10 d.
EU Cyber Resilience Act: Single Reporting Platform Goes Live2026 m. rugsėjo 10 d. From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through ENISA’s Single Reporting Platform within 24 hours. Internal reporting workflows and platform access credentials should be in place now. Why should I read this?The EU Cyber Resilience Act (CRA) reporting regime goes live on 11 September 2026. From that date, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through the Single Reporting Platform (SRP), operated by the EU Agency for Cybersecurity (ENISA). One submission reaches the relevant national cybersecurity authorities across the EU. The clock is short: an early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report within 14 days of a fix for vulnerabilities or within one month for incidents. Registering on the platform takes minutes and is only needed when a report is due; what takes time is the internal workflow to detect, decide and file within 24 hours. Full application of the CRA, including penalties, follows on 11 December 2027. What should I do?Manufacturers should act now on platform access, internal process design and reporting-scope review.
What else do I need to know about the CRA Single Reporting Platform?One submission, cross-border reachThe manufacturer submits one notification through the SRP, addressed simultaneously to the CSIRT designated as coordinator and to ENISA. The coordinating CSIRT disseminates without delay to CSIRTs in Member States where the product is available. Delegated Regulation (EU) 2026/881, adopted in December 2025, permits delayed dissemination where justified on cybersecurity grounds. This includes cases where the security of the SRP itself has been compromised. Parallel obligations under NIS2 and DORA do not go awayThe CRA is product-focused; NIS2, the EU directive on cybersecurity of essential and important entities, is entity-focused. Both use a 24-hour/72-hour structure, but the obligations run in parallel. Once a corrective measure is available, ENISA adds the reported vulnerability to the European vulnerability database established under NIS2. DORA, the Digital Operational Resilience Act, applies to financial entities and their information and communication technology (ICT) third-party risk; CRA obligations do not displace DORA incident reporting. Organisations under both regimes should map the overlaps now. What comes next: Conformity assessment, standards and penaltiesFull CRA application follows on 11 December 2027, when the essential cybersecurity requirements, conformity assessment, market surveillance and penalties take effect. Fines are set by each Member State within EU ceilings of up to EUR 15 million or 2.5% of worldwide turnover, and imposed by national market surveillance authorities. Micro and small enterprises cannot be fined for missing the 24-hour deadline. The harmonised standards that will give manufacturers a presumption of conformity are still being developed. The Commission’s guidance of 27 July 2026 explains the reporting obligations in practice and is worth reading alongside ENISA’s platform guidance. Open-source software stewards will also be subject to reporting obligations from 11 December 2027, to the extent they are involved in developing the products. Voluntary reporting through the SRP will follow in a later phase. Further reading on the CRA Single Reporting Platform
Pagrindiniai kontaktai
Robbert Santifort Partner Roterdamas, Netherlands Olaf van Haperen Partner Roterdamas, Netherlands Maarten Stassen Partner Briuselis, Belgija Caroline Lyannaz Partner Paryžius, France Nils Müller Partner Miunchenas, Vokietija | Hamburgas, Vokietija Joanna Kulewska Knowledge Lawyer Briuselis, Belgija Naujausios publikacijos
Naujausios naujienos
Naujausios renginiai
guides and reports 2026 m. rugsėjo 10 d. EU Cyber Resilience Act: Single Reporting Platform Goes Live legal updates 2026 m. rugsėjo 10 d. Hong Kong: PCPD issues further guidance on best practices in the use of age... legal updates 2026 m. rugsėjo 10 d. Global Life Sciences & Healthcare Bulletin legal updates 2026 m. rugsėjo 09 d. EU Sustainability Omnibus Package: key changes and implications for busines... įmonės naujienos 2026 m. rugpjūčio 26 d. Eversheds Sutherland strengthens top-ranked pensions practice with appointm... klientų naujienos 2026 m. rugpjūčio 13 d. Eversheds Sutherland advises H.I.G. Capital on investment in Phoenix ME klientų naujienos 2026 m. rugpjūčio 13 d. Eversheds Sutherland reappointed to the UK's Government Commercial Agency l... įmonės naujienos 2026 m. rugpjūčio 12 d. William A. Nelson, Former Investment Adviser Association Policy Leader, Joi... in-person Basic foundations of US employment law 2026 m. rugsėjo 17 d. 9.30am - 4.30pm (GMT) Londonas, Jungtinė Karalystė in-person 2026 BDC Roundtable 2026 m. rugsėjo 23 d. Washington DC, Jungtinės Amerikos Valstijos virtual Employment law in the Kingdom of Saudi Arabia 2026 m. rugsėjo 29 d. 9.30am - 12.30pm (BST) Virtual in-person Labor relations conference - turning legal change into workplace reality 2026 m. spalio 08 d. 10.00am - 4.00pm (BST) Londonas, Jungtinė Karalystė |