Cyber Resilience Act reporting obligations now in force: ENISA launches single reporting platform
The Cyber Resilience Act (CRA), which entered into force in December 2024, is designed to improve the cybersecurity of connected products and software placed on the EU market. While the majority of the CRA's product cybersecurity requirements will only become applicable on 11 December 2027, the reporting obligations under Article 14 take effect today.
What changes from today?
Manufacturers must now notify:
- Actively exploited vulnerabilities affecting products with digital elements.
- Severe incidents that impact the security of those products.
The reporting timeline is demanding:
- Early warning within 24 hours of becoming aware of the incident or vulnerability.
- Detailed notification within 72 hours.
- Final report within 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability, or within one month for a severe incident.
Importantly, these obligations apply not only to newly placed products but also to products with digital elements that are already available on the EU market.
ENISA's Single Reporting Platform goes live
To support compliance, ENISA has launched the CRA Single Reporting Platform (SRP), providing manufacturers with a centralised reporting mechanism across the European Union. The platform enables organisations to submit a single report that is shared with the relevant national authorities, avoiding multiple national notifications.
According to ENISA, the platform is intended to strengthen coordinated vulnerability management and support a more resilient European digital ecosystem. Juhan Lepassaar, Executive Director of ENISA, highlighted that timely reporting and information sharing are essential to protecting critical sectors and improving cybersecurity resilience across the Digital Single Market.
The platform is available at: https://portal.cra-srp.enisa.europa.eu/
Access requires an EU Login account.
Importance for the fire safety and security sector
For manufacturers in the fire safety, security, access control, alarm, video surveillance and building technologies sectors, the CRA represents a significant shift in regulatory expectations. Increasingly, products such as fire detection systems, alarm control panels, access management systems and connected life-safety devices rely on software, cloud connectivity and remote maintenance capabilities.
The CRA introduces a lifecycle approach to cybersecurity, requiring manufacturers not only to design secure products, but also to monitor vulnerabilities, manage incidents and maintain effective reporting processes. Today's reporting obligations are therefore an early indicator of the more comprehensive compliance framework that will apply from December 2027.
If you manufacture or place connected products on the EU market should ensure that:
- Internal incident-response procedures are aligned with the CRA reporting deadlines.
- Responsible personnel have access to the ENISA SRP.
- EU Login accounts and reporting workflows are established in advance.
- Product vulnerability management processes can support the required reporting and follow-up actions.