ENISA launches EU Cyber Resilience Act reporting platform
The initial capability of a single EU platform for manufacturers to report actively exploited vulnerabilities and severe incidents went live on 11 September.
Event / data period: 2026-09-11
Published: · Updated:
The European Union Agency for Cybersecurity (ENISA) deployed the initial operating capability of the Cyber Resilience Act’s Single Reporting Platform on 11 September 2026. The platform lets manufacturers and certain open-source software stewards report actively exploited vulnerabilities and severe security incidents through one mechanism.
A designated national CSIRT first receives a notification and shares relevant information with other member-state CSIRTs where the affected product is available; ENISA receives it at the same time. Reporting obligations for manufacturers began on 11 September, and ENISA said it would expand the platform’s functions based on operational experience.
Data
Security development
Security event or institutional action reported by the source.
- · Occurred
CRA Single Reporting Platform launched with initial capability
ENISA deployed an initial operating capability for manufacturers and covered open-source software stewards to report actively exploited vulnerabilities and severe incidents through one platform.
Methodology
The event date and description summarise the action reported by the source; no additional measurement or forecast is made.
Updated:
Subjects and places
Subject proposals
- Cyber crimeSuggested
- Subject suggested from the title or summary: exploited vulnerabilitieswww.enisa.europa.eu ↗