Guia independente do Regulamento (UE) 2024/2847 · Estado: em vigor
Esta página é uma tradução automática (IA) e não foi revista por uma pessoa. Os artigos do blogue estão disponíveis apenas em inglês.
← All news
Análises do CRA24 August 2026

Eighteen Days to CRA Reporting: What You Can Prepare Before the Platform Opens on 11 September 2026

Eighteen Days to CRA Reporting: What You Can Prepare Before the Platform Opens on 11 September 2026

On 11 de setembro de 2026, Article 14 of the Cyber Resilience Act starts to apply and manufacturers must report actively exploited vulnerabilities and severe incidents through ENISA's plataforma de notificação única. That is eighteen days away. The platform is not open yet, which sounds like a reason to wait. It is not. Between the guidance ENISA published in July and August 2026 and the regulation itself, almost every decision that makes a first report go smoothly can be taken now, with no login required.

Status at publication, 24 August 2026

The Single Reporting Platform is ainda não está em serviço. Its public URL will be published on ENISA's SRP hub before the platform goes live, the list of national CSIRTs designated as coordinators is still to come, and no reporting API is offered at this stage. ENISA has scheduled the platform to be operational by 11 de setembro de 2026. Everything below is preparation you can complete without access to the system.

1. Create the EU Login accounts today

Registration runs through EU Login, and ENISA says the account can be created in advance. Nothing about it involves a CSIRT, a queue or an approval, so nobody who might file a report should be creating one during an incident. Do it for the primary filer and at least one deputy.

Platform registration itself is a different matter. ENISA advises manufacturers to register on the SRP and start validation only when they have a specific notification to submit, so as not to overload the national teams before launch. Both things can be true: create the EU Login now, leave the SRP account until you need it.

2. Settle your product classification in advance

The notification form asks for the product type, meaning default, important or critical, and, where the product is not default, the Anexo III or Anexo IV category. That answer is informed by Commission Implementing Regulation (EU) 2025/2392 of 28 November 2025, which describes the core functionality of each category. It is not a question to work through with an exploited vulnerability in front of you. Our ferramenta de classificação e o matriz de conformidade will get you to a defensible answer in a short sitting, and the result belongs in your incident runbook, not in someone's memory.

3. Work out which CSIRT is yours

Reports route to the CSIRT designado como coordenador in the Member State of your main establishment, and Article 14(7) sets out how to determine that. ENISA will publish the list of designated coordinators in due course, but the underlying question does not depend on the list: where is the main establishment, and if the manufacturer is outside the EU, where is the Article 18 authorised representative established? Record the answer now.

4. Draft the wording before you need it

The mandatory set at the 24-hour early warning is small: notification type and level, manufacturer or steward name, product, a title, and for incidents whether malicious acts are suspected. The substance becomes mandatory at 72 horas, and the full description, severity and impact in the final report. The early warning is an alert, not an investigation.

Two details from ENISA's guidance shape where that drafting should live. Drafts saved in the platform are visible only to the representative who created them, so a colleague picking up a handover will not see them. And there is no API at this stage, so every notification is typed in by a person. Keep skeleton wording for each stage in a document your incident team already shares, and use the platform to transcribe rather than to compose. Our guia de notificação sets out what each stage has to contain.

5. Decide who is on the clock

A 24-hour deadline running from the moment the organisation becomes aware is, in practice, a staffing question. The platform provides a primary representative and a backup who joins by email invitation. Decide now who holds each seat, who covers holidays and weekends, and how an engineer who spots active exploitation on a Saturday reaches that person. Our support planner is a good place to record it.

6. Know which clocks run, and which do not

This is frequently muddled. The 24-hour e 72 horas windows run from awareness, and nothing pauses them. What can be delayed is dissemination: the receiving CSIRT may hold a notification back from other Member States on the grounds specified in Commission Delegated Regulation (EU) 2026/881, adopted on 11 December 2025. A manufacturer may separately flag the narrow conditions in artigo 16(2) in its 72-hour notification, which limits what ENISA sees until the coordinating CSIRT releases the full text. That restricts content, not timing. The final report has its own clock: for a vulnerability, no later than 14 dias after a corrective measure is available; for a severe incident, within um mês of the 72-hour notification.

Where this leaves you

None of the six items above needs the platform, a URL or an announcement. They need an afternoon. The companies that will find 11 de setembro de 2026 uneventful are the ones that spend it now, so that the only new thing on the day of a first report is the login screen. Our state of play page tracks what is still outstanding.

Published 24 August 2026 · CRA Insights. Part of the CRA insights blog on cyberresilienceact.eu.