Vellum Search Regulations coveredPricingAnalysis ↗ Sign in

Single Reporting Platform (SRP)

EU — ENISA (Cyber Resilience Act) · 2026-07-17 · EU · verified record

Themes: Cybersecurity

Ecosystems: EU Cyber Resilience Act

The Single Reporting Platform (SRP) provided for in the Cyber Resilience Act (CRA) shall become a technical tool to use for the reporting of actively exploited vulnerabilities and incidents impacting products with digital elements operating in the EU Digital Single Market. The SRP will be used by CSIRTs and manufacturers for mandatory reporting and could be used by any natural/legal persons for voluntary reporting. The CRA mandates manufacturers of products with digital elements to report actively exploited vulnerabilities and severe incidents having an impact on the security of the product as

The Single Reporting Platform (SRP) provided for in the Cyber Resilience Act (CRA) shall become a technical tool to use for the reporting of actively exploited vulnerabilities and incidents impacting products with digital elements operating in the EU Digital Single Market. The SRP will be used by CSIRTs and manufacturers for mandatory reporting and could be used by any natural/legal persons for voluntary reporting. The CRA mandates manufacturers of products with digital elements to report actively exploited vulnerabilities and severe incidents having an impact on the security of the product as of 11 September 2026 onwards using the Single Reporting Platform. Throughout 2025 and 2026, ENISA is undertaking a number of necessary steps to support the successful implementation of the platform. The CRA brings transparency to the vulnerability disclosure processes and strengthens how EU CSIRTs can mitigate risks stemming from vulnerabilities. Further information: Regulation - 2024/2847 - EN - EUR-Lex Frequently Asked Questions Updated: 17 July 2026 This is a collection of frequently asked questions on Cyber Resilience Act Single Reporting Platform (CRA SRP). Document is intended for publication on ENISA website and to be updated during implementation of CRA SRP Please see also information about CRA reporting https://digital-strategy.ec.europa.eu/en/policies/cra-reporting in particular FAQ file there https://ec.europa.eu/newsroom/dae/redirection/document/122331 - 1. What is the Cyber Resilience Act’s Single Reporting Platform (CRA SRP)? - CRA SRP will be a centralized electronic system designed to simplify the reporting obligations for manufacturers and open-source software stewards under the Cyber Resilience Act. It will serve as a "single entry point", allowing for manufacturers to report actively exploited vulnerabilities and severe incidents having an impact on the security of products with digital elements only once, rather than having to notify multiple national authorities individually. Manufacturers will submit notifications electronically through the platform, which will allow them select CSIRT designated as coordinator (based on the location of the manufacturer's main establishment - see CRA Article 14(7) on determining relevant CSIRT for reporting) and ENISA simultaneously.…

Read verified records — free.

Sign in to read this record in the app with full provenance, themes and related developments — free, 20 searches a day, no card needed.

Read in Vellum Search →   Official source ↗