Regulations & Compliance

ENISA’s CRA Reporting Platform Opens Friday: Mandatory Filings Only, No API

The Cyber Resilience Act’s reporting clock starts on Friday 11 September and ENISA has now set out what its Single Reporting Platform will do on day one. According to the agency’s FAQ, updated on 4 September, the platform will accept only mandatory notifications of actively exploited vulnerabilities and severe incidents under Articles 14 and 24. Voluntary reporting is switched off, there is no API and the public address had not been published when the FAQ was last revised. Every manufacturer selling hardware or software with digital elements into the EU files through it including for products already on the market.

Article 14 of Regulation (EU) 2024/2847 gives a manufacturer 24 hours from becoming aware of an actively exploited vulnerability or a severe incident to file an early warning, 72 hours for a notification with an initial assessment and a final report within 14 days of a fix becoming available for vulnerabilities or one month after the 72-hour notification for incidents. Article 64(2) puts breaches of Article 14 in the regulation’s top penalty band: up to €15 million or 2.5% of worldwide annual turnover. The rest of the CRA, including the engineering requirements in Article 13 and Annex I, applies from 11 December 2027.

The Dashboard Clock Runs 24 Hours Fast

One detail in the FAQ deserves a second read. In the current release, the platform’s 72-hour counter shows the notification as due 48 hours after the early warning was submitted, not 72 hours after the manufacturer became aware. ENISA acknowledges that a report can therefore display as overdue before the legal deadline has passed says the counters are reminders rather than the obligation itself and promises a correction in a later release.

A regulator launching a compliance platform whose clock disagrees with its own regulation is not reassuring. The deadline is the one in Article 14 and nothing on a dashboard changes it. Keep your own timestamp for the moment of awareness because that is the number a market surveillance authority will ask for.

Filing is manual. ENISA says no API will be offered at launch, so every notification is typed into the web interface and companies with many products keep their own tracking. If the platform is down, the FAQ’s answer is to wait and file when it returns. You may contact your CSIRT directly in the meantime but the platform filing is still required.

One Primary Representative, Up To 20 Deputies

Access runs on personal EU Login accounts with multi-factor authentication. Each manufacturer has one primary assigned representative who can invite up to 20 secondary representatives and the national CSIRT validates the link between person and company after registration. Validation runs in parallel, a representative who has not yet been validated can file up to 20 notifications before validation becomes mandatory. ENISA’s advice is not to register until there is something to report, since registration takes a few minutes with an existing EU Login account. Create the accounts now for the primary representative and a deputy. Register on the platform only when you need it.

A Sponsored Post Asks the Right Question

On 8 September BleepingComputer ran a piece by Shane Warden, principal architect at ActiveState, headed “The EU CRA’s Real Question, What Shipped and When Did You Know?” It is sponsored content and ActiveState sells pre-vetted open source components with contractual remediation times so read it as an advertisement with a byline. Warden’s argument is that until December 2027 the CRA is a visibility obligation rather than a security one, it can only be met by knowing which components are in each shipped version and when a problem in one of them first became known. He supports this with two vendor statistics from Black Duck and Edgescan. They are left out here; they are sales collateral, not evidence.

His anecdote is more useful than his numbers. Warden describes receiving a signed disclosure listing 95 supposed vulnerabilities in an open source project he helps maintain of which two or three were real followed by a demand for $100,000 to keep the report private. That is his own account and cannot be checked, but it lands on the CRA’s hardest question. The 24 hours run from reliable evidence that a malicious actor has exploited the flaw and deciding what counts as reliable is a judgement a named person will have to make at speed, sometimes on a Friday evening.

The European Commission’s own FAQ, which ENISA points to, settles one adjacent question. A manufacturer does not have to retrospectively report exploitation it already knew about before 11 September. A vulnerability known for years that turns out to be exploited on 12 September must be filed.

Swedish Filings Go To CERT-SE

ENISA’s list of coordinating CSIRTs, also updated on 4 September, names CERT-SE for Sweden and points to cert.se/rapportera. Finland’s entry is Kyberturvallisuuskeskus at Traficom and Denmark’s is the Danish Defence Intelligence Service, home of the Centre for Cyber Security. The rule is the Member State where decisions about the product’s cybersecurity are predominantly taken and a group files once per vulnerability regardless of how many EU subsidiaries it has. Sweden has not yet passed its complementary national provisions; the government inquiry SOU 2025:115 proposed Post- och telestyrelsen as market surveillance authority. The reporting duty does not wait for that because a regulation applies directly.

Axis Communications in Lund is a clear example of who is caught. AXIS OS runs on network cameras and other devices sold across the EU and the company published its own CRA explainer in June together with a podcast on the regulation recorded with chip supplier NXP, the named expert is Andre Bastert, the product manager responsible for AXIS OS. Every Nordic maker of connected hardware, embedded firmware or commercial software is in the same position from Friday, with or without an explainer.

Three things can be done before Friday without the platform. Create EU Login accounts with MFA for a primary representative and a deputy. Write down who decides that evidence of exploitation is reliable and who decides when that person is on holiday. Then take one product shipped six months ago and time how long it takes to state what is in it and when you first heard of its last critical CVE, the test Warden proposes. If that takes longer than 72 hours, the platform is not your problem.

References

  1. Frequently Asked Questions on the CRA Single Reporting Platform
  2. List of CSIRTs Designated as Coordinators
  3. Cyber Resilience Act: Reporting Obligations
  4. Regulation (EU) 2024/2847, the Cyber Resilience Act
  5. The EU CRA’s Real Question: What Shipped, and When Did You Know?
  6. How the EU Cyber Resilience Act Is Changing the Security Rules

This post is also available in: Svenska

Per Häggdahl

Per Häggdahl is Head of Business Unit and CISO at eBuilder Security, with more than 20 years securing systems for banks, central banks, stock exchanges and central securities depositories, now leading the team that brings that same enterprise-grade protection to organisations of every size.