Cyber Resilience Act Single Reporting Platform
ENISA’s SRP is the official technical system for mandatory CRA vulnerability and incident reporting.
The Cyber Resilience Act establishes a Single Reporting Platform managed by ENISA. From 11 September 2026, manufacturers use the platform for mandatory notifications of actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements.
A single entry point
ENISA describes the SRP as a centralized electronic system that allows reporting once rather than separately notifying multiple national authorities. The manufacturer selects the relevant CSIRT coordinator, and the platform handles the statutory routing.
CRA Report does not replace the SRP
CRA Report is deliberately a preparation layer. It helps structure the assessment, timeline and draft reporting content locally, then points the user to the official ENISA workflow for submission.
Why not submit automatically?
Keeping the product as a local preparation tool reduces the amount of highly sensitive vulnerability and incident data that must cross third-party infrastructure. ENISA’s current FAQ also states that no reporting API will be provided at this stage.