規則(EU)2024/2847に関する独立したガイド · ステータス:発効中
このページは自動(AI)翻訳であり、人によるレビューは行われていません。 ブログ記事は英語のみで提供されています。
← All news
CRAインサイト14 September 2026

ENISA's SRP FAQ, Restamped 12 September 2026: The Tutorial Video Is Live and the Factsheet Now Ships in Nine Languages

ENISA's SRP FAQ, Restamped 12 September 2026: The Tutorial Video Is Live and the Factsheet Now Ships in Nine Languages

ENISA restamped the Single Reporting Platform's FAQ page 12 September 2026, a day after the CRA's reporting obligations and the platform itself went live. Checking the page today, two of the gaps our own coverage flagged at launch have closed: the AR User Tutorial Video ENISA promised is now live, and the SRP Factsheet, English-only at launch, now ships in nine languages. Two new FAQ entries also appeared, covering how to report a security problem in the platform itself.

Status at publication, 14 September 2026

The Single Reporting Platform is live and accepting mandatory notifications under Article 14. Voluntary reporting under 第15条 is still not available, with no date attached. The platform still does not record when a manufacturer became aware of an actively exploited vulnerability; the SRP Glossary notes that field is scheduled for "the next release", with no date given. No Application Programming Interface is offered.

The tutorial video and the translated factsheet

At launch, ENISA's own account of the platform listed tutorial videos among the material still to come. The AR User Tutorial Video is now published on the SRP hub page, a step-by-step walkthrough of the platform for Assigned Representatives. Alongside it, the SRP Factsheet, available only in English when reporting started, now has versions in German, Greek, French, Hungarian, Latvian, Dutch, Romanian, Slovenian and Swedish, with ENISA saying it will continue to translate supporting material into the remaining EU languages. The platform interface itself remains English only.

Two new FAQ entries, and the counter and outage guidance made official

The FAQ gained an entry on reporting a security issue in the platform itself, separate from the CRA reporting obligation the platform exists to serve: a dedicated mailbox, cra-srp-security@enisa.europa.eu, with a published PGP key, and a second address for responsible disclosure of platform vulnerabilities. It also now states plainly, in its own numbered entry, what languages the platform supports and when that might change.

The FAQ also formalises, in its own numbered entries, two points our 報告ガイド already tracks in detail from earlier guidance: that the on-screen 72-hour counter runs 48 hours from your early-warning submission rather than from awareness, and does not replace the Article 14 duty; and that if the SRP is temporarily unavailable, you should wait and file once it returns, or contact your CSIRT directly if immediate communication is necessary, with the filing still required through the platform afterwards. Neither behaviour is new since launch. What is new is that both now have a citable, numbered FAQ answer rather than sitting only in ENISA's earlier guidance pages.

What hasn't moved

第15条 voluntary reporting still has no date. The field recording when a manufacturer became aware of an actively exploited vulnerability is still absent, so the moment Article 14 actually measures from remains one only your own records capture. No Application Programming Interface is offered, and none is promised for this release. And the CRA's other deadlines have not moved either: no harmonised standard is yet cited in the Official Journal, so the Article 27 presumption of conformity remains unavailable, a gap our 現況 page continues to track.

Published 14 September 2026 · CRA Insights. Part of the CRA insights blog on cyberresilienceact.eu.