Published Monday, September 14, 2026 at 11:24 AM PT

<strong>ENISA CRA Single Reporting Platform Activated β€” Manufacturer Vulnerability Reporting Now Mandatory (EU)</strong>

BLUF: ENISA switched on the EU Cyber Resilience Act’s Single Reporting Platform on 11 September 2026, the same date binding manufacturer reporting obligations commenced. Any software vendor or hardware manufacturer selling into EU markets must now report actively exploited vulnerabilities to ENISA via this platform or face regulatory penalties.

DETAILS:

  • ENISA launched the platform 11 September 2026 under Article 16(1) of the CRA; legal reporting obligations became binding manufacturers the same day.
  • The platform is ENISA-built and ENISA-operated. It serves as the single centralized intake for vulnerability reports from manufacturers and vendors in CRA scope.
  • Reporting obligation applies to actively exploited vulnerabilities. Scope of “in scope” products still being clarified by ENISA but centers on EU critical infrastructure and digital services.
  • ENISA simultaneously expanded CVE Root to 20 Coordinating CVE Numbering Authorities to strengthen vulnerability coordination infrastructure supporting the platform.
  • Reporting mechanics (timelines, formats, escalation paths) are being published; full operational guidance expected within weeks.

IMPACT:

  • Who: Software vendors, hardware manufacturers, any organization with products/services under CRA jurisdiction in EU markets.
  • What: Mandatory disclosure of actively exploited vulns; non-compliance incurs EU administrative fines (penalty structure codified in CRA).
  • Scope: Effective immediately for vulns discovered on or after 11 September 2026. Organizations already holding zero-day knowledge of exploited issues face immediate reporting duty.

RECOMMENDED ACTIONS:

  • Today: Audit which products/services fall under CRA scope. Designate single point of contact for ENISA reporting.
  • 72 hours: Build internal process to detect and triage actively exploited vulnerabilities. If uncertain whether a vuln qualifies, report.
  • Before next discovery: Locate ENISA CRA Single Reporting Platform URL (check ENISA.eu) and complete organizational registration.
  • Ongoing: Monitor ENISA for published timelines and data requirements; plan internal workflows around reporting deadlines.

SOURCES:
Help Net Security; Industrial Cyber; multiple corroborating sources confirm platform activation and binding obligation start date.


Recent high-severity events at publish time:

Recent high-severity events