ENISA has deployed the initial operating capability of the Single Reporting Platform (SRP) to support the Cyber Resilience Act (CRA) reporting obligations. From 11 September 2026 manufacturers and open‑source software stewards must report actively exploited vulnerabilities and severe incidents through the SRP. The platform enables coordinated notification to national CSIRTs and ENISA.
Why it matters: The SRP provides a single, EU‑wide tool for manufacturers to meet CRA reporting duties, enhancing coordinated cybersecurity risk management.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.