What to prepare before opening ENISA’s Single Reporting Platform
An operational preflight for manufacturers preparing a CRA vulnerability or severe-incident notification before entering the official SRP.
What you need to know
Before opening ENISA’s CRA Single Reporting Platform, prepare a reviewed incident packet containing the occurrence type, awareness time, manufacturer and affected-product details, known EU market availability, a concise occurrence summary, current mitigation status, user actions where relevant, sensitivity considerations and the owner of unresolved facts. The SRP is the official submission channel, so preparation should make portal entry a handoff rather than a fresh investigation.
Key takeaways
- ENISA describes the SRP as the CRA single entry point for mandatory reporting.
- Prepare the report stage before portal entry so the submission session is not where your team discovers missing facts.
- Keep 24-hour, 72-hour and final-report content separate because each stage has a different purpose and information maturity.
- Do not send sensitive incident details to unrelated SaaS systems just to format the report.
What is the Single Reporting Platform?
The CRA requires notifications to be submitted through a Single Reporting Platform established by ENISA. ENISA describes it as a centralized electronic system intended to let manufacturers report once rather than making separate notifications to multiple national authorities.
The current ENISA FAQ says manufacturers will select the relevant CSIRT coordinator in the platform and that the system will handle the statutory routing. The platform is scheduled to be operational by 11 September 2026, when mandatory Article 14 reporting begins.
Why should you prepare outside the portal first?
The official platform is the place to submit, not the ideal place to coordinate an unfinished investigation. If engineering, product security and legal are still debating basic facts while someone is inside the submission workflow, the portal becomes an expensive collaboration surface.
A better pattern is to prepare a stage-specific packet first, complete an internal review, then transfer the approved content into the SRP.
What should be ready for the 24-hour stage?
Prepare the occurrence type, the awareness record, affected product, known Member State availability where applicable, and the concise information needed for the early warning. For severe incidents, Article 14 requires at least whether the incident is suspected of being caused by unlawful or malicious acts.
The goal is not to make the first stage look like a final forensic report. It is to provide the required early information without waiting for facts that can mature later.
What should be ready for the 72-hour stage?
For an actively exploited vulnerability, the fuller notification includes available general information about the affected product, the nature of the exploit and vulnerability, corrective or mitigating measures, measures users can take and any applicable sensitivity indication.
For a severe incident, the notification includes available general information about the nature of the incident, an initial assessment, corrective or mitigating measures, user actions and any applicable sensitivity indication.
What should remain outside the reporting packet?
Do not copy entire forensic archives, raw secrets, unnecessary customer data or unrelated internal communications into the preparation layer. Keep the evidence in the systems intended to protect it and bring forward only the information needed to support the regulatory submission.
What does a good preflight look like?
- Confirm the likely reporting path and stage.
- Confirm awareness time and timezone.
- Confirm manufacturer identity and affected product details.
- Record known EU market availability.
- Draft the occurrence summary in plain language.
- Record mitigations already taken and user actions where relevant.
- Mark sensitivity considerations for review.
- List missing facts and owners.
- Have the submission owner review the packet before portal entry.
- Preserve the actual SRP submission confirmation afterward.
Does CRA Report submit to ENISA?
No. CRA Report is deliberately a preparation layer. It helps structure the likely path, deadlines, missing information and staged report content locally in the browser. The final official submission remains in ENISA’s SRP.
Official references
Verify against the live official sources
CRA Report is a preparation tool. Regulatory guidance and the ENISA reporting workflow can change, so final decisions and submissions should be checked against the current Regulation, Commission guidance and ENISA SRP documentation.