Oberoende vägledning till förordning (EU) 2024/2847 · Status: i kraft
Denna sida är en automatisk (AI-)översättning och har inte granskats av en person. Blogginlägg finns endast på engelska.
← All news
CRA Insights20 August 2026Uppdaterad 11 september 2026

ENISA Capped an Unverified SRP Account at Ten Notifications, Then Doubled It to Twenty

ENISA Capped an Unverified SRP Account at Ten Notifications, Then Doubled It to Twenty

On 14 augusti 2026, ENISA published a fourth guidance page for the Cyber Resilience Act's gemensamma rapporteringsplattformen, covering the assigned representative's interface. There was no announcement. It documents everything that is not the notification form: settings, manufacturer associations, the dashboard and the alerts tab. Two facts in it have not appeared before, and both change how to prepare for 11 september 2026.

Updated 11 September 2026

The headline figure changed, and the disagreement it created has outlived go-live. ENISA rewrote its SRP FAQ on 4 september 2026 och doubled the cap to 20 notifications per manufacturer, updated that FAQ again on 10 september 2026 without disturbing the figure, and left this 14 August guidance page saying ten. The two ENISA documents still disagree on the day the platform opened, and the FAQ is the newer text. Two other things below were overtaken: the list of designated CSIRTs has since been published, and the webinar ENISA planned no longer appears in its guidance. Everything else on this page still holds.

Status at 11 September 2026

The Single Reporting Platform opened on 11 september 2026 at portal.cra-srp.enisa.europa.eu, with sign-in through EU Login and multi-factor authentication required. ENISA published an AR User Manual and platform terms and conditions on 10 september 2026; the tutorial videos promised at launch have not appeared. Voluntary reporting under Article 15 did not arrive, and there is still no reporting API.

An unverified account could file ten notifications, now twenty

The page explains how to attach your account to an additional manufacturer through Association Management. The association is created with the status Unverified, and a verification request goes to the CSIRT designated as coordinator. Then comes the sentence: as an unverified assigned representative, you can submit only up to 10 notifications. ENISA has since doubled that: the FAQ rewritten on 4 september 2026 puts the ceiling at 20 notifications for one manufacturer before validation becomes mandatory, and adds that there can be one Primary representative and up to 20 Secondary ones.

That is the first quantified limit ENISA has published, and it sits beside the reassurance given on 3 augusti 2026 that validation by a CSIRT is not a precondition for reporting. Both can hold at once: you are not blocked while you wait, but the door is not open indefinitely. ENISA does not say what happens at the eleventh attempt, whether the ceiling counts events or individual submissions, or whether it also applies to the association created during first registration rather than added later.

Twenty is generous for a single-product company and still finite for a group filing across several legal entities. Verification is not urgent, but it is not optional either, and that conversation with your coordinating CSIRT is better had before a clock is running. Note also that the 14 August guidance page has not been revised, so a compliance folder holding the older figure is now wrong by half.

Your backup representative cannot see your drafts

The dashboard section is blunt: it shows only the drafts du själv har skapat, and you cannot view drafts created by another representative associated with the same manufacturer. Drafts are private to their author.

Consider two in the morning. Someone starts a 24-hour early warning, saves a draft, then becomes unreachable. The backup opens the dashboard and finds nothing. The 24-hour window runs from the moment the manufacturer became aware and nothing pauses it, so the backup starts from a blank form. The fix is not technical: draft the wording outside the platform, in a document your incident team already shares, and use the platform to transcribe it. Our rapporteringsguide sets out what each stage must contain.

Account housekeeping now has a documented shape

A primary representative invites a backup by email address, creating a record marked Pending Invitation with no role until it is accepted. A secondary representative can request promotion, which goes to the coordinating CSIRT for review. Either can remove an association, which is then marked Deleted. And a single account can carry associations with several manufacturers.

That last point matters for groups with several entities, and for firms acting under Article 18 as authorised representatives for non-EU manufacturers. It is also where the naming trap bites. ENISA's assigned representative is a platform login role; the Article 18 auktoriserade representant is a legal appointment with statutory duties. One person can hold several of the first while being none of the second.

Red alerts mean a CSIRT has pushed back

The alerts tab is colour coded. Unread alerts are light blue and turn grey once opened. Red alerts appear only when something exceptional has happened, and the example ENISA gives is a designated CSIRT that har ogiltigförklarat en inlämning.

Filing is therefore not the end of the exchange, and no deadline in Article 14 moves because a submission came back. Whoever watches that tab has to be watching it on a Sunday, which argues for a monitored team mailbox behind both seats rather than two personal addresses.

A helpdesk address, and two links to check

The rebuilt hub now publishes a support address, cra-srp-helpdesk [at] enisa.europa.eu, the first direct contact point ENISA has offered for SRP questions. That hub currently points its AR Interface functions link at the notification submission page, so reach the new page through the Innehåll list at the top. And the old ENISA addresses still serve the 31 juli 2026 text, while the new Product Security location carries 3 August and 14 August stamps. A bookmark in your compliance folder is probably the stale copy. ENISA repeated the pattern in September, moving its field Glossary to a second address when it issued version 1.1 on 5 september 2026.

Four things to do before 11 September

  • Create the EU Login accounts for your primary and backup representatives now. That step involves no CSIRT and no waiting.
  • Write the text of your 24-hour early warning outside the platform, where both representatives can open it.
  • Settle the fields the form demands, in particular whether your product is standard, viktig or kritisk and which Annex III or IV category it falls in. Our Klassificeringsverktyget answers that in a few clicks.
  • Put a monitored mailbox behind both seats, and decide who reads the alerts tab out of hours.

One more, added since: do not read the platform's countdown as your deadline. ENISA's September FAQ explains that the 72-timmarsräknaren runs from submission of the 24-hour report rather than from awareness, so a filing can show as overdue before the legal deadline has passed. The platform exists now, and every item on that list is still something you settle away from it. Our timeline page tracks what ENISA has left to publish.

Published 20 August 2026, uppdaterad 11 september 2026 · CRA Insights. Part of the CRA insights blog on cyberresilienceact.eu.