ENISA SRP

Cyber Resilience Act Single Reporting Platform

ENISA’s SRP is the official technical system for mandatory CRA vulnerability and incident reporting.

The Cyber Resilience Act establishes a Single Reporting Platform managed by ENISA. From 11 September 2026, manufacturers use the platform for mandatory notifications of actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements.

A single entry point

ENISA describes the SRP as a centralized electronic system that allows reporting once rather than separately notifying multiple national authorities. The manufacturer selects the relevant CSIRT coordinator, and the platform handles the statutory routing.

CRA Report does not replace the SRP

CRA Report is deliberately a preparation layer. It helps structure the assessment, timeline and draft reporting content locally, then points the user to the official ENISA workflow for submission.

Why not submit automatically?

Keeping the product as a local preparation tool reduces the amount of highly sensitive vulnerability and incident data that must cross third-party infrastructure. ENISA’s current FAQ also states that no reporting API will be provided at this stage.

Always use ENISA’s current SRP documentation at submission time. The platform and its guidance are still being implemented and updated ahead of the mandatory reporting date.

Official source

Open ENISA’s Single Reporting Platform documentation.