ENISA Activates CRA Single Reporting Platform, Mandating Timely Disclosure of Actively Exploited Vulnerabilities
What Happened – On 11 September 2026 the EU Agency for Cybersecurity (ENISA) launched the Cyber Resilience Act (CRA) Single Reporting Platform. The portal obliges any manufacturer placing a product with digital elements on the EU market to report actively exploited vulnerabilities and severe incidents within strict time‑frames (24 h early warning, 72 h initial assessment, 14 d final report, or 30 d for severe incidents).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for a continuous incident‑response and reporting process that can produce auditable evidence within the CRA deadlines.
- Highlights the importance of centralized governance of product‑level security incidents, including designated primary and secondary representatives and a clear CSIRT coordination model.
- Shows that organizations must map reporting obligations to a control‑objective (e.g., “Incident Management and Reporting”) that satisfies multiple frameworks (NIST CSF 2.0, ISO 27001, GDPR, etc.).
Who Is Affected – Manufacturers of digital‑enabled products across all sectors (software, IoT, embedded systems, SaaS platforms) that sell into the EU Digital Single Market.
Recommended Actions
- Update your incident‑response playbook to embed CRA reporting timelines and assign a Primary Assigned Representative.
- Integrate the ENISA web portal workflow (or future API) into your security‑operations ticketing system to capture evidence automatically.
- Map the CRA reporting requirement to the control objective “Incident Management and Reporting” in your existing control framework and collect the supporting artifacts for audit readiness.
Source: Help Net Security
Technical Notes – The platform currently accepts manual web‑form submissions; an API is planned for a later phase. Registration uses EU‑Login with multi‑factor authentication. Manufacturers must select a national CSIRT as coordinator; incorrect selection can invalidate the report.
Source: Help Net Security