The CRA doesn't ask you to work out which national authority to notify, in which format, in which language. It gives you one door. Understanding how that door works — and that it isn't quite open yet — is part of being ready for September 2026.
What the SRP is
The Single Reporting Platform is the electronic system, operated by ENISA, through which manufacturers submit CRA notifications. The design principle is report once: you file a single notification and the platform handles distribution, rather than each manufacturer contacting multiple national bodies for the same event. It covers both reporting streams — actively exploited vulnerabilities and severe incidents — across all three stages of the 24 / 72 / 14 timeline.
Where a report goes
When you submit, the platform routes the notification to the CSIRT designated as coordinator in the member state where you have your main establishment, and makes it available to ENISA at the same time. In defined circumstances the information can be shared more widely among national authorities. The practical consequence for you: identify your coordinating CSIRT in advance, because that's the authority the platform will route your reports to and the one you'll deal with.
Its status in mid-2026
As of mid-2026 the platform is not yet operational and exposes no public API, with a testing period expected ahead of the 11 September 2026 reporting date. This is the awkward reality of preparing for a reporting obligation whose reporting mechanism is still being stood up.
The absence of an API matters for anyone hoping to automate submission: at launch, filing is likely to be a human action against a web interface, not a machine-to-machine call. Plan for structured export and manual submission, and treat direct integration as something to add when the interface exists.
Being ready before it's live
You can't submit to a platform that isn't open, but you can be in a position to submit the instant it is. Readiness has three parts:
- Know your coordinating CSIRT — the destination the platform will route to.
- Hold SRP-aligned report content — structured drafts for both streams and all three stages, so you're assembling from a template, not a blank page, when a 24-hour clock is running.
- Rehearse — a dry-run or tabletop of the whole path, from detection to a completed report, so the process isn't first exercised during a real incident.
All of that depends on the harder upstream question — is our product actually affected, and is this reportable — which is the subject of the reporting pillar and what counts as actively exploited.
Frequently asked
What is the ENISA Single Reporting Platform?
It is the single electronic platform through which manufacturers submit the CRA’s vulnerability and incident notifications. You report once, and the platform routes the notification to the CSIRT designated as coordinator in your member state of main establishment and, simultaneously, to ENISA.
Is the ENISA SRP live yet?
As of mid-2026 it is not yet operational and exposes no public API, with a testing period expected before the 11 September 2026 reporting date. Manufacturers should prepare structured, SRP-aligned reports and rehearse the process rather than wait for the platform.
Do I report to my national authority or to ENISA?
You report once to the Single Reporting Platform. It handles the distribution — to the coordinating CSIRT of your member state of main establishment and to ENISA — so you don’t file the same event separately with multiple authorities.