Eighteen Days to CRA Reporting: What You Can Prepare Before the Platform Opens on 11 September 2026
On 2026 m. rugsėjo 11 d., Article 14 of the Cyber Resilience Act starts to apply and manufacturers must report actively exploited vulnerabilities and severe incidents through ENISA's Viena pranešimų pateikimo platforma. That is eighteen days away. The platform is not open yet, which sounds like a reason to wait. It is not. Between the guidance ENISA published in July and August 2026 and the regulation itself, almost every decision that makes a first report go smoothly can be taken now, with no login required.
The Single Reporting Platform is dar neveikia. Its public URL will be published on ENISA's SRP hub before the platform goes live, the list of national CSIRTs designated as coordinators is still to come, and no reporting API is offered at this stage. ENISA has scheduled the platform to be operational by 2026 m. rugsėjo 11 d.. Everything below is preparation you can complete without access to the system.
1. Create the EU Login accounts today
Registration runs through EU Login, and ENISA says the account can be created in advance. Nothing about it involves a CSIRT, a queue or an approval, so nobody who might file a report should be creating one during an incident. Do it for the primary filer and at least one deputy.
Platform registration itself is a different matter. ENISA advises manufacturers to register on the SRP and start validation only when they have a specific notification to submit, so as not to overload the national teams before launch. Both things can be true: create the EU Login now, leave the SRP account until you need it.
2. Settle your product classification in advance
The notification form asks for the product type, meaning default, important or critical, and, where the product is not default, the III priedas or IV priedas category. That answer is informed by Commission Implementing Regulation (EU) 2025/2392 of 28 November 2025, which describes the core functionality of each category. It is not a question to work through with an exploited vulnerability in front of you. Our klasifikavimo įrankis ir atitikties matrica will get you to a defensible answer in a short sitting, and the result belongs in your incident runbook, not in someone's memory.
3. Work out which CSIRT is yours
Reports route to the koordinatoriumi paskirtas CSIRT in the Member State of your main establishment, and Article 14(7) sets out how to determine that. ENISA will publish the list of designated coordinators in due course, but the underlying question does not depend on the list: where is the main establishment, and if the manufacturer is outside the EU, where is the Article 18 authorised representative established? Record the answer now.
4. Draft the wording before you need it
The mandatory set at the 24-hour early warning is small: notification type and level, manufacturer or steward name, product, a title, and for incidents whether malicious acts are suspected. The substance becomes mandatory at 72 valandos, and the full description, severity and impact in the final report. The early warning is an alert, not an investigation.
Two details from ENISA's guidance shape where that drafting should live. Drafts saved in the platform are visible only to the representative who created them, so a colleague picking up a handover will not see them. And there is no API at this stage, so every notification is typed in by a person. Keep skeleton wording for each stage in a document your incident team already shares, and use the platform to transcribe rather than to compose. Our pranešimų teikimo gidas sets out what each stage has to contain.
5. Decide who is on the clock
A 24-hour deadline running from the moment the organisation becomes aware is, in practice, a staffing question. The platform provides a primary representative and a backup who joins by email invitation. Decide now who holds each seat, who covers holidays and weekends, and how an engineer who spots active exploitation on a Saturday reaches that person. Our support planner is a good place to record it.
6. Know which clocks run, and which do not
This is frequently muddled. The 24-hour ir 72 valandų windows run from awareness, and nothing pauses them. What can be delayed is dissemination: the receiving CSIRT may hold a notification back from other Member States on the grounds specified in Commission Delegated Regulation (EU) 2026/881, adopted on 11 December 2025. A manufacturer may separately flag the narrow conditions in 16 straipsnio 2 dalyje in its 72-hour notification, which limits what ENISA sees until the coordinating CSIRT releases the full text. That restricts content, not timing. The final report has its own clock: for a vulnerability, no later than 14 dienų after a corrective measure is available; for a severe incident, within vieną mėnesį of the 72-hour notification.
Where this leaves you
None of the six items above needs the platform, a URL or an announcement. They need an afternoon. The companies that will find 2026 m. rugsėjo 11 d. uneventful are the ones that spend it now, so that the only new thing on the day of a first report is the login screen. Our state of play page tracks what is still outstanding.
