ENISA Published the List of Coordinating CSIRTs for All 27 Member States on 4 September 2026
Since the Cyber Resilience Act's reporting rules were adopted, one practical question has had no published answer: which national team actually receives your notification. ENISA's FAQ said the list of CSIRTs designated as coordinators would come at a later stage. On 4 September 2026, exactly one week before reporting starts, it arrived, alongside a near-total rewrite of the Single Reporting Platform FAQ.
The Single Reporting Platform is dar neveikia. Its public URL has still not been published; ENISA says it will appear on the SRP page before the platform goes live, and that the platform is scheduled to be operational from 2026 m. rugsėjo 11 d.. ENISA has now also confirmed that no reporting API will be offered in the initial release, and that voluntary reporting under Article 15 will not be available at launch.
The list tells you who, not whether
The new page, stamped 04/09/2026, is a plain table: a Member State on the left, one or more contact URLs for its coordinating CSIRT on the right. Ireland points to a dedicated NCSC page for the CRA; Spain gives two separate INCIBE routes, one for incidents and one for vulnerability coordination. All 27 Member States are covered.
What it does not do is tell you which row is yours. That still comes from Article 14(7), and the test is narrower than most organisations assume: your main establishment is the Member State where decisions about the cybersecurity of your products are predominantly taken, which may be a development site rather than a registered office. Where that cannot be determined, the fallback is your largest EU headcount; with no EU establishment, the order runs authorised representative, importer, distributor, then most users. Our pranešimų teikimo gidas sets out the stages and what each must contain.
Voluntary reporting is not there on day one
The 2026 m. liepos 31 d. FAQ said voluntary reporting would be enabled after 11 September 2026. The 4 September 2026 version is firmer and later: on 11 September the platform will accept only mandatory notifications under Articles 14 and 24, and Article 15 voluntary notification moves to a future phase with no date. Nothing legally required is missing, but a disclosure process that planned to route non-exploited vulnerabilities through the SRP has nowhere to send them.
The 72-hour counter does not count from awareness
The most useful new answer is also the least advertised. ENISA explains that in the current release the platform's 72-hour counter shows a due date 48 hours after the 24-hour report is submitted, not 72 hours after the manufacturer became aware. ENISA states plainly that a notification may therefore display as overdue before 72 hours have run from awareness, and that the logic will change in a later release to use the awareness timestamp instead.
ENISA is equally plain that the counters exist for visibility and do not replace the duty in Article 14. Together those give a simple rule: keep your own clock, started at awareness and recorded in your incident log. Filing your early warning quickly, which is what the law wants, makes the on-screen counter stricter than the legal one. An on-screen overdue flag is not a finding of non-compliance, and a green counter is not a defence.
What to do if the platform is unavailable
A second new answer covers outages. If the SRP is temporarily unavailable, ENISA says to wait and submit once it returns; where immediate communication is necessary meanwhile, you may contact your designated CSIRT directly, but the notification must still go through the SRP afterwards. Worth stating clearly, because ENISA does not: nothing in the CRA pauses the 24-hour, 72-hour, 14-day or one-month windows during an outage. Timestamp the outage and the direct contact, and keep both.
Account limits have moved
The cap on filing before your CSIRT has validated you has doubled: the guidance of 14 August 2026 put it at 10 notifications, the new FAQ says 20 per manufacturer. There can be one Primary assigned representative and up to 20 Secondary ones. EU Login accounts are personal, multi-factor authentication is required, and ENISA advises against functional mailboxes. Note that ENISA's assigned representative is a platform login role, not the Article 18 authorised representative, which is a legal appointment.
What has not changed
None of this moves a deadline. The manufacturer cannot delay pranešimo pateikimo: the windows run from awareness. It is the receiving CSIRT that may delay onward dissemination, under Commission Delegated Regulation (EU) 2026/881, adopted on 2025 m. gruodžio 11 d.. Separately, 16 straipsnio 2 dalyje lets a manufacturer flag narrow conditions in the 72-hour notification, limiting what ENISA sees until the receiving CSIRT releases the full text. That is a restriction on content, not extra time.
Four days remain, and the work left is not technical:
- Identify your coordinating CSIRT under Article 14(7) and write down the reasoning.
- Create the EU Login accounts, with multi-factor authentication, for both representatives.
- Settle whether your product is default, important or critical, which our klasifikavimo įrankis answers in a few clicks.
- Draft your 24-hour wording somewhere both representatives can reach it.
Our state of play page tracks what is still outstanding before 11 September.
