Guia independente do Regulamento (UE) 2024/2847 · Estado: em vigor
Esta página é uma tradução automática (IA) e não foi revista por uma pessoa. Os artigos do blogue estão disponíveis apenas em inglês.
← All news
Análises do CRA14 September 2026

ENISA's SRP FAQ, Restamped 12 September 2026: The Tutorial Video Is Live and the Factsheet Now Ships in Nine Languages

ENISA's SRP FAQ, Restamped 12 September 2026: The Tutorial Video Is Live and the Factsheet Now Ships in Nine Languages

ENISA restamped the Single Reporting Platform's FAQ page 12 September 2026, a day after the CRA's reporting obligations and the platform itself went live. Checking the page today, two of the gaps our own coverage flagged at launch have closed: the AR User Tutorial Video ENISA promised is now live, and the SRP Factsheet, English-only at launch, now ships in nine languages. Two new FAQ entries also appeared, covering how to report a security problem in the platform itself.

Status at publication, 14 September 2026

The Single Reporting Platform is live and accepting mandatory notifications under Article 14. Voluntary reporting under artigo 15.º is still not available, with no date attached. The platform still does not record when a manufacturer became aware of an actively exploited vulnerability; the SRP Glossary notes that field is scheduled for "the next release", with no date given. No Application Programming Interface is offered.

The tutorial video and the translated factsheet

At launch, ENISA's own account of the platform listed tutorial videos among the material still to come. The AR User Tutorial Video is now published on the SRP hub page, a step-by-step walkthrough of the platform for Assigned Representatives. Alongside it, the SRP Factsheet, available only in English when reporting started, now has versions in German, Greek, French, Hungarian, Latvian, Dutch, Romanian, Slovenian and Swedish, with ENISA saying it will continue to translate supporting material into the remaining EU languages. The platform interface itself remains English only.

Two new FAQ entries, and the counter and outage guidance made official

The FAQ gained an entry on reporting a security issue in the platform itself, separate from the CRA reporting obligation the platform exists to serve: a dedicated mailbox, cra-srp-security@enisa.europa.eu, with a published PGP key, and a second address for responsible disclosure of platform vulnerabilities. It also now states plainly, in its own numbered entry, what languages the platform supports and when that might change.

The FAQ also formalises, in its own numbered entries, two points our guia de notificação already tracks in detail from earlier guidance: that the on-screen 72-hour counter runs 48 hours from your early-warning submission rather than from awareness, and does not replace the Article 14 duty; and that if the SRP is temporarily unavailable, you should wait and file once it returns, or contact your CSIRT directly if immediate communication is necessary, with the filing still required through the platform afterwards. Neither behaviour is new since launch. What is new is that both now have a citable, numbered FAQ answer rather than sitting only in ENISA's earlier guidance pages.

What hasn't moved

artigo 15.º voluntary reporting still has no date. The field recording when a manufacturer became aware of an actively exploited vulnerability is still absent, so the moment Article 14 actually measures from remains one only your own records capture. No Application Programming Interface is offered, and none is promised for this release. And the CRA's other deadlines have not moved either: no harmonised standard is yet cited in the Official Journal, so the Article 27 presumption of conformity remains unavailable, a gap our ponto de situação page continues to track.

Published 14 September 2026 · CRA Insights. Part of the CRA insights blog on cyberresilienceact.eu.