ENISA's 14 August 2026 SRP Guidance Caps an Unverified Account at Ten Notifications
On 14 August 2026, ENISA published a fourth guidance page for the Cyber Resilience Act's Plataforma Única de Notificación, covering the assigned representative's interface. There was no announcement. It documents everything that is not the notification form: settings, manufacturer associations, the dashboard and the alerts tab. Two facts in it have not appeared before, and both change how to prepare for 11 de septiembre de 2026.
The Single Reporting Platform is aún no está operativa. Its public URL is still unpublished, the list of national CSIRTs designated as coordinators is still not out, and no reporting API is offered at this stage. ENISA has scheduled it to be operational by 11 de septiembre de 2026 and plans a webinar two weeks before service starts. Everything below describes a system nobody outside the CSIRTs Network can yet log in to.
An unverified account can file only ten notifications
The page explains how to attach your account to an additional manufacturer through Association Management. The association is created with the status Unverified, and a verification request goes to the CSIRT designated as coordinator. Then comes the sentence: as an unverified assigned representative, you can submit only up to 10 notifications.
That is the first quantified limit ENISA has published, and it sits beside the reassurance given on 3 August 2026 that validation by a CSIRT is not a precondition for reporting. Both can hold at once: you are not blocked while you wait, but the door is not open indefinitely. ENISA does not say what happens at the eleventh attempt, whether the ceiling counts events or individual submissions, or whether it also applies to the association created during first registration rather than added later.
Ten is generous for a single-product company and thin for a group filing across several legal entities. Verification is not urgent, but it is not optional either, and that conversation with your coordinating CSIRT is better had before a clock is running.
Your backup representative cannot see your drafts
The dashboard section is blunt: it shows only the drafts created by you, and you cannot view drafts created by another representative associated with the same manufacturer. Drafts are private to their author.
Consider two in the morning. Someone starts a 24-hour early warning, saves a draft, then becomes unreachable. The backup opens the dashboard and finds nothing. The 24-hour window runs from the moment the manufacturer became aware and nothing pauses it, so the backup starts from a blank form. The fix is not technical: draft the wording outside the platform, in a document your incident team already shares, and use the platform to transcribe it. Our guía de notificación sets out what each stage must contain.
Account housekeeping now has a documented shape
A primary representative invites a backup by email address, creating a record marked Pending Invitation with no role until it is accepted. A secondary representative can request promotion, which goes to the coordinating CSIRT for review. Either can remove an association, which is then marked Deleted. And a single account can carry associations with several manufacturers.
That last point matters for groups with several entities, and for firms acting under Article 18 as authorised representatives for non-EU manufacturers. It is also where the naming trap bites. ENISA's assigned representative is a platform login role; the Article 18 representante autorizado is a legal appointment with statutory duties. One person can hold several of the first while being none of the second.
Red alerts mean a CSIRT has pushed back
The alerts tab is colour coded. Unread alerts are light blue and turn grey once opened. Red alerts appear only when something exceptional has happened, and the example ENISA gives is a designated CSIRT that has invalidated a submission.
Filing is therefore not the end of the exchange, and no deadline in Article 14 moves because a submission came back. Whoever watches that tab has to be watching it on a Sunday, which argues for a monitored team mailbox behind both seats rather than two personal addresses.
A helpdesk address, and two links to check
The rebuilt hub now publishes a support address, cra-srp-helpdesk [at] enisa.europa.eu, the first direct contact point ENISA has offered for SRP questions. That hub currently points its AR Interface functions link at the notification submission page, so reach the new page through the Content list at the top. And the old ENISA addresses still serve the 31 de julio de 2026 text, while the new Product Security location carries 3 August and 14 August stamps. A bookmark in your compliance folder is probably the stale copy.
Four things to do before 11 September
- Create the EU Login accounts for your primary and backup representatives now. That step involves no CSIRT and no waiting.
- Write the text of your 24-hour early warning outside the platform, where both representatives can open it.
- Settle the fields the form demands, in particular whether your product is por defecto, importante or crítico and which Annex III or IV category it falls in. Our herramienta de clasificación answers that in a few clicks.
- Put a monitored mailbox behind both seats, and decide who reads the alerts tab out of hours.
The platform is three weeks from existing. Every item on that list can be done without it. Our timeline page tracks what ENISA has left to publish.
