← Back to CRA Insights
Vulnerability handling

The CRA Single Reporting Platform Is Live: How to Register Before You Need It

Reporting obligations under Article 14 of the Cyber Resilience Act became mandatory on 11 September 2026. Until that same day, the tool you were supposed to report through did not exist for public use. ENISA's CRA Single Reporting Platform (SRP) went live at portal.cra-srp.enisa.europa.eu on 11 September 2026, with access instructions, user manuals and terms of service published the day before. If your organisation hasn't registered yet, the clock on your first actively exploited vulnerability or severe incident won't wait for you to figure out the portal.

What the SRP is for

The SRP is the single channel for the notifications Article 14 requires: an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident, a fuller notification with an initial assessment within 72 hours, and a final report within 14 days of a corrective or mitigating measure becoming available. The clock starts when the manufacturer becomes aware of the event, not when the platform is convenient.

In this first release, the SRP is a web interface only - no API yet - and it operates in English, with other languages planned later.

Who registers, and as what

Access runs through EU Login with multi-factor authentication enabled. Each manufacturer (or open-source steward) needs at least one Primary Assigned Representative (AR) and can add up to 20 Secondary ARs.

Primary AR registration is a direct, self-service process:

  1. Authenticate through EU Login (MFA required).
  2. Select your CSIRT Designated as Coordinator (CDaC) - in practice, the national CSIRT tied to your primary EU establishment.
  3. Accept the platform's legal terms.
  4. Confirm your personal details and enter your manufacturer information.
  5. Your account becomes Active with the AR Primary User role.

Secondary AR registration starts with an email invitation from a verified Primary AR. The invited person authenticates via EU Login, confirms their pre-filled details, and accepts the manufacturer association - but that invitation link expires after seven days, so it needs to be actioned promptly rather than left in an inbox.

One detail worth flagging to whoever owns this internally: association validation by the designated CSIRT happens after registration, not before. A pending AR can already begin working in the system - which is one more reason not to leave this until the middle of an actual incident.

Choosing your CSIRT coordinator matters

The CSIRT you select as your CDaC becomes the entity that receives your notifications and forwards them to other Member States affected by the same vulnerability or incident. For most manufacturers this is a straightforward lookup based on where their primary EU establishment sits - but multinationals with several EU entities should decide this deliberately, once, rather than have it decided by whoever happens to be registering that day.

Building the process behind the login

Registration is the easy part. What the platform doesn't do for you is the harder work: standing up an internal detection and triage process that can actually recognise an actively exploited vulnerability or a severe incident when it happens, and route it to whoever holds the Primary or Secondary AR role fast enough to hit the 24-hour early warning. If you haven't already read it, our PSIRT explainer covers who inside your organisation should own that function.

What to do this week

  • Confirm who in your organisation will hold the Primary AR role, and register them.
  • Add Secondary ARs for backup coverage - a single point of failure on a 24-hour clock is a bad idea.
  • Identify your CDaC now, before an incident forces a rushed decision.
  • Run a dry registration and, if your process allows it, a test notification, so the first time your team touches the SRP isn't during a live incident.

The reporting deadline was fixed months in advance. The platform arrived on the day it was due. The gap left for most manufacturers is operational readiness, not legal uncertainty - and that gap closes fastest by registering now rather than after the next actively exploited CVE lands on your desk.