Project · read-only readiness aid

CRA SRP Readiness

Source-linked preparation aids for published Cyber Resilience Act reporting clocks and the ENISA Single Reporting Platform.

This sample is non-authoritative. It is not legal advice, a compliance certification, an applicability determination, official ENISA schema/API/field validation, or a report-submission service. It contains no real incident data.

Source re-checked 11 September 2026 · corpus 2026-09-11.1

Primary Commission and ENISA pages were re-checked on the reporting start date. Re-check the linked primary guidance before filing: a dated source check does not make this sample authoritative. View the guidance changelog →

Published rules in this sample

Reporting start · 11 September 2026

Mandatory CRA manufacturer reporting obligations enter into application on 11 September 2026. European Commission source ↗

Early warning · within 24 hours

Early warning is due without undue delay and in any case within 24 hours of awareness. European Commission source ↗

Notification · within 72 hours

Full vulnerability or incident notification is due without undue delay and in any case within 72 hours of awareness. European Commission source ↗

Final vulnerability report · 14 days

The final report for an actively exploited vulnerability is due no later than 14 days after a corrective measure is available. European Commission source ↗

Final severe-incident report · one month

The final report for a severe incident is due within one month after the initial notification. European Commission source ↗

Single Reporting Platform

ENISA describes the CRA Single Reporting Platform as the single entry point for CRA notifications and schedules it to be operational by 11 September 2026. ENISA FAQ ↗

Deadline clock aid

These clocks use elapsed time; weekends do not pause them. The awareness timestamp drives the 24h and 72h aids. The corrective-measure timestamp drives the 14-day vulnerability-final aid.



Operational aid only: the legal trigger and facts must still be verified against current guidance.

Stage-field preparation checklist

This is a non-exhaustive preparation checklist, not a mirror of official fields. Confirm every item against the current ENISA interface guide/FAQ at filing time.

Early warning · prepare before the 24h window
72h notification · enrich the prepared payload
Final vulnerability report · prepare from corrective-measure availability

Known platform readiness traps

Assigned Representative limit conflict

The 14 August interface-guide reporting says an unverified Assigned Representative can represent up to 10 manufacturers, while the ENISA FAQ has stated 20. Treat this as unresolved guidance, not a rule to automate. 14 Aug interface-guide summary ↗ · ENISA FAQ ↗

Draft visibility warning

ENISA guidance says drafts are private to their author; a backup representative cannot rely on seeing another user's draft during a 24-hour window. Keep a controlled shared preparation copy outside SRP and define the hand-off owner before an incident. ENISA FAQ ↗


Back to top ↑
Rodion · rodion.place · Contact · RSS · Source