Project · read-only readiness aid
CRA SRP Readiness
Source-linked preparation aids for published Cyber Resilience Act reporting clocks and the ENISA Single Reporting Platform.
This sample is non-authoritative. It is not legal advice, a compliance certification, an applicability determination, official ENISA schema/API/field validation, or a report-submission service. It contains no real incident data.
Primary Commission and ENISA pages were re-checked on the reporting start date. Re-check the linked primary guidance before filing: a dated source check does not make this sample authoritative. View the guidance changelog →
Published rules in this sample
Mandatory CRA manufacturer reporting obligations enter into application on 11 September 2026. European Commission source ↗
Early warning is due without undue delay and in any case within 24 hours of awareness. European Commission source ↗
Full vulnerability or incident notification is due without undue delay and in any case within 72 hours of awareness. European Commission source ↗
The final report for an actively exploited vulnerability is due no later than 14 days after a corrective measure is available. European Commission source ↗
The final report for a severe incident is due within one month after the initial notification. European Commission source ↗
ENISA describes the CRA Single Reporting Platform as the single entry point for CRA notifications and schedules it to be operational by 11 September 2026. ENISA FAQ ↗
Deadline clock aid
These clocks use elapsed time; weekends do not pause them. The awareness timestamp drives the 24h and 72h aids. The corrective-measure timestamp drives the 14-day vulnerability-final aid.
Operational aid only: the legal trigger and facts must still be verified against current guidance.
Stage-field preparation checklist
This is a non-exhaustive preparation checklist, not a mirror of official fields. Confirm every item against the current ENISA interface guide/FAQ at filing time.
- Awareness timestamp and internal owner recorded.
- Manufacturer/contact and product/version identifiers ready.
- Concise vulnerability or incident summary and known exploitation/severity facts ready.
- Source evidence and hand-off notes stored outside the SRP draft.
- Affected products/versions and available technical assessment reviewed.
- Impact, exploitation/incident scope, mitigations and corrective-action status updated.
- Representative access and submission responsibility confirmed.
- Corrective-measure availability timestamp recorded.
- Remediation, disclosure and closure facts reconciled with prior stages.
- Current ENISA guidance re-checked before submission.
Known platform readiness traps
The 14 August interface-guide reporting says an unverified Assigned Representative can represent up to 10 manufacturers, while the ENISA FAQ has stated 20. Treat this as unresolved guidance, not a rule to automate. 14 Aug interface-guide summary ↗ · ENISA FAQ ↗
ENISA guidance says drafts are private to their author; a backup representative cannot rely on seeing another user's draft during a 24-hour window. Keep a controlled shared preparation copy outside SRP and define the hand-off owner before an incident. ENISA FAQ ↗
Back to top ↑
Rodion · rodion.place · Contact · RSS · Source