Reminder: CRA Reporting Obligations Start on 11 September 2026
A reminder that the reporting obligations under the Cyber Resilience Act (CRA) will become applicable on 11 September 2026. Manufacturers of products with digital elements will be required to report actively exploited vulnerabilities and severe cybersecurity incidents affecting the security of their products.
While the final production URL for submitting notifications has not yet been published, ENISA has already made available information on the Single Reporting Platform (SRP). Registration guidance, reporting instructions, and information on notification formats and processes are already available.
Organizations affected by the CRA are encouraged to familiarize themselves with the reporting requirements and prepare their internal processes before the reporting obligations take effect.
