11 September 2026 marks an important milestone in the implementation of the EU Cyber Resilience Act (CRA). From today, manufacturers of products with digital elements are legally required to report actively exploited vulnerabilities and severe cybersecurity incidents through the new CRA Single Reporting Platform (SRP), operated by ENISA.