From 11 September 2026 on, the reporting obligations under the Cyber Resilience Act (CRA
) will apply. These apply to manufacturers of products with digital elements as defined by the CRA
who make their products available on the European Union (EU
) internal market. Reporting is required for actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements.
The CRA
Single Reporting Platform (CRA
-SRP
), operated by the European Union Agency for Cybersecurity (ENISA
), is the central, EU
-wide, standardised reporting platform for the CRA
, which operates in English. Manufacturers submit their reports only once. The report is made available simultaneously to the competent CSIRT
designated as the coordinator and to ENISA
. The coordinating CSIRT
may subsequently pass on the information to other affected CSIRTs
and, where necessary, to the competent market surveillance authorities. In Germany, the CRA
Market Surveillance unit, like the CERT
-Bund, is based at the BSI
as the coordinating CSIRT
.
The notification regarding the CRA
-SRP
does not replace any other obligations the manufacturer may have to inform affected users and, where necessary, to recommend appropriate protective measures to them.
Source: BSI
An EU
Login account is required to access the site.
Further information is provided in the following sections and is available on ENISA
’s CRA
-SRP website.
Note
Please note that there is no obligation to register before a report needs to be submitted
CRA
-SRP
registration and submission of reports can be completed within a few minutes if required.
Definition of the two reporting categories
The following definitions apply to the classification of events subject to reporting under the CRA
.
Actively exploited vulnerability
In accordance with Article 3 (42) of the CRA, this is a vulnerability for which there is reliable evidence that a malicious actor has demonstrably exploited it in a system without permission.
The following two conditions must be met for a vulnerability to be subject to mandatory reporting:
- The vulnerability is present in a product with digital elements.
- There is credible evidence of actual exploitation in real-world systems.
A published exploit (code to exploit the vulnerability), proof-of-concept code or port scans are not sufficient. A vulnerability that is theoretically exploitable but not actively exploited is not subject to the CRA
reporting obligation.
Severe incidents having impact on products with digital elements
A severe incident affecting the security of a product is defined in accordance with Article 3 (44) and Article 14 (5) of the CRA
and must meet at least one of the following conditions:
- The severe incident compromises, or may compromise, the product’s ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions.
- The severe incident has led, or may lead, to the injection or execution of malicious code in the product or in a user’s network.
Example: A ransomware incident at a manufacturer is not automatically a severe incident within the meaning of the CRA
. For it to be classified as such, it would have to affect the security of the product or be capable of leading to the manipulation of software, updates, signature keys or product functions.
Reporting variants
For each reporting category, there are three progressive reporting variants. The information is supplemented step by step. Information already recorded is carried over.
Reports must be written in English to enable efficient EU
-wide coordination.
Early warning
The early warning must specify, in particular, the report category, the manufacturer, the affected product and a descriptive title. In the case of a severe incident, it must also be stated whether there is any suspicion that it is attributable to unlawful or malicious acts. Where already known, additional details regarding the incident, the vulnerability and the affected EU
Member States may be provided.
Detailed notification
The more detailed report supplements and elaborates on the information provided in the early warning.
In the case of an actively exploited vulnerability, the following information in particular must be provided, where available:
- a general description of the vulnerability and its exploitation,
- an initial assessment,
- corrective or risk-mitigation measures already taken,
- measures that users can take themselves,
- an assessment of the sensitivity of the information provided.
In the event of a severe incident, the following details in particular must be provided:
- the nature and time of the incident,
- initial assessment of the incident,
- corrective or risk mitigation measures already taken,
- possible measures for users,
- assessment of the sensitivity of the information.
Final report
In the case of an actively exploited vulnerability, the final report shall include, in particular:
- a full description of the vulnerability,
- severity and impact,
- details of the attacker, where known,
- details of the security update or other protective measures,
- the date on which the remedy became available.
The final report on a vulnerability must be submitted no later than 14 days after a corrective or protective measure becomes available.
In the event of a severe incident, the final report shall include, in particular:
- a detailed description of the severe security incident,
- its severity and impact,
- the nature of the threat or probable cause,
- remedial measures already implemented and those still in progress.
Until the final report is submitted, manufacturers may update reports that have already been submitted. The CRA
-SRP
automatically informs the coordinating CSIRT
, ENISA
and, where applicable, any other CSIRTs
already involved of any changes.
Further information on submitting reports
Once the final report has been submitted, the report can generally no longer be edited by the person submitting it.
Reporting deadlines
Under Article 14 (2) (actively exploited vulnerability) and Article 14 (3) (severe incident), the following deadlines apply to the sequential reporting stages:
- An early warning must be issued within 24 hours following reliable information received by the manufacturer regarding an actively exploited vulnerability or a severe incident affecting products with digital elements.
- A more detailed report within 72 hours.
- A final report must be submitted within 14 days of a remedy or protective measure (e.g. a security update) being made available in the case of an actively exploited vulnerability, and one month after the previous, more detailed report in the case of a severe incident affecting products with digital elements.
Manufacturer roles
The report is submitted by a representative appointed by the manufacturer (Assigned Representative (AR
)). The CRA
-SRP
distinguishes between:
- a Primary Assigned Representative as the primary representative and
- a Secondary Assigned Representative as an additional or deputy representative.
Both roles can submit reports on behalf of the assigned manufacturer. The Primary Assigned Representative may invite further Secondary Assigned Representatives.
Saved drafts are visible only to the person who created the draft in question. Other Assigned Representatives of the same manufacturer cannot view these drafts.
Open-in accordance with Article 24 (3) of the CRAded to enable voluntary notifications by natural or legal persons
The following steps are required for initial registration:
- Select the role of Assigned Representative.
- Select the relevant country, with the designated CSIRT
acting as coordinator. - Authenticate via EU
Login. - Accept the legal terms of use.
- Check the pre-filled personal details.
- Enter details of the manufacturer you represent.
- Invite a representative.
The individual steps are outlined on ENISA
’s CRA
-SRP
website:
Which CSIRT
acting as a coordinator is responsible is generally determined by the manufacturer’s main establishment within the EU
. For manufacturers without a main establishment in the EU
, the additional criteria set out in Article 14 (7) of the CRA
apply.
Frequently Asked Questions (FAQ
)
Please find the most frequently asked questions (FAQ
) to date and the corresponding answers in the following table.
-
Only in this exceptional case should you send the mandatory CRA
report by email to the Federal Computer Emergency Response Team, CERT
-Bund. -
Yes, the CRA
-SRP
is in English so that reports can be processed and shared across the EU
. -
Yes, this can happen.
In this case, the incident must be reported both under NIS-2
and under the CRA
. You may include a reference note in the relevant reportUnder the Digital Omnibus proposed by the European Commission, Article 23 of NIS-2
is to be supplemented with the following paragraph 12:2. Article 23 is amended as follows:
b) the following paragraph 12 is added:
“When a manufacturer notifies a severe incident pursuant to Article 14(3) of Regulation (EU
) 2024/2847 and the incident reporting under that Article contains relevant information as required under paragraph 4 of this Article, the reporting of the manufacturer under Article 14(3) of Regulation (EU
) 2024/2847 shall constitute reporting of information under paragraph 4 of this Article.”If the provision is adopted in this form, duplicate reporting under NIS-2
and the CRA
could be avoided. Reportingding information obligations under NIS-2 -
From 11 September 2026, the CRA
-SRP
reporting obligations will initially apply. The remaining provisions of the CRA
will generally apply from 11 December 2027.However, it is advisable to take the recommendations of the on the into account at an early stage.
-
A separation between PSIRT
and CSIRT
may be advisable so that actively exploited vulnerabilities in the organisation’s own products and severe incidents within its own network can each be addressed using appropriate resources.Depending on the product portfolio, the size of the organisation and the IT
infrastructure, the same individuals may perform both roles and act as stand-ins for one another.Regardless of organisational structure, reliable cover should be ensured by at least two people.
-
No, the same personal requirements apply to the Primary AR
and Secondary AR
(backup user).However, the Secondary AR
must be set up using the invitation function to ensure that the assignment to the manufacturer is correct. -
The role of Assigned Representative is not tied to a specific position within the company.
The person should, in principle, be able to carry out a technical assessment of the product portfolio or work closely with the relevant technical product team.
In large organisations, this task may, for example, be undertaken by a member of a Product Security Incident Response Team (PSIRT
), which is responsible for managing vulnerabilities in the organisation’s own products throughout the entire product lifecycle.In smaller organisations, the role may, for example, be taken on by a member of the development team.
A contact person responsible for EU
regulation who is in close contact with the technical product team is also a suitable candidate.It is crucial that this person is able to assess the necessary details in the reporting form and either respond immediately to enquiries from the coordinating CSIRT
– for example, regarding protective measures – or obtain the required information in a timely manner. -
Provided the conditions are met, CERT
-Bund, which is based at the Federal Office for Information Security (BSI
), is the designated coordinating CSIRT
.The criteria for determining this are set out in Article 14 (7) of the CRA.
-
An overview of the available methods for two-factor authentication can be found on the following webpage:
The EU
Login app is available for Android and iOS.A single EU
Login account can be linked to several mobile phones, each with the EU
Login app installed separately. -
Not at present. The EU
-wide standardised CRA
Single Reporting Platform is the only platform of fulfilling the CRA
reporting obligation.It is conceivable that national reporting platforms may be integrated at a later date. The ‘Digital Omnibus’ legislative package proposed by the European Commission provides for the harmonisation of reporting channels.
Further information can be found in the FAQ
on the CRA
-SRP on the ENISA
website.
Please also refer to Chapter 5, ‘Reporting obligations of manufacturers’, in the European Commission’s CRA
FAQs.
Similar topics
Short URL:
https://www.bsi.bund.de/dok/cra-srp-en
