Summary
- Manufacturers must now report actively exploited vulnerabilities and severe security incidents under the Cyber Resilience Act.
- ENISA’s Single Reporting Platform provides one electronic route for notifications to reach the appropriate national authorities.
- The reporting regime brings legal deadlines directly into product security, vulnerability management, and technology supply chains well before the CRA applies in full.
Europe’s Cyber Resilience Act has moved from implementation planning into operational compliance, with manufacturers now required to report actively exploited vulnerabilities and severe security incidents through a new EU-wide system operated by ENISA.
The European Union Agency for Cybersecurity launched the initial operating capability of its Single Reporting Platform on 11 September, the same day that the first reporting obligations under the CRA became applicable. Manufacturers of products with digital elements must use the platform when an actively exploited vulnerability or qualifying severe incident affects the security of their products.
The wider legislation will not apply in full until December 2027, but reporting has deliberately arrived earlier, giving regulators and manufacturers a working mechanism for handling security problems while companies prepare for broader requirements covering product design, vulnerability management, software support, and security throughout the product lifecycle. Techopia examined the incoming rapid-reporting regime earlier this month; those deadlines have now become part of ordinary product-security operations.
ENISA’s platform is intended to simplify a regulatory process that would otherwise span multiple national authorities. Instead of sending separate notifications across different jurisdictions, manufacturers can report once, after which the relevant information is made available to the appropriate computer security incident response teams and other authorities.
Although one reporting portal removes some administrative duplication, the more difficult work still sits inside the manufacturer. Companies need processes capable of recognising when a vulnerability is actively exploited, deciding whether an incident meets the regulatory threshold, gathering enough information for an early warning, and escalating it before the statutory deadline expires.
That process can bring product engineers, security teams, legal staff, compliance functions, suppliers, and senior management into the same incident while the technical facts are still developing. Vulnerability disclosure that might once have remained largely within a security or engineering function can now trigger a formal European regulatory workflow before remediation is complete.
Juhan Lepassaar, executive director of ENISA, said: “Vulnerabilities in digital products are often exploited by threat actors to subvert or hamper critical services, such as healthcare, energy, transport or telecommunications. The streamlined reporting and sharing of information on actively exploited vulnerabilities and severe incidents helps to build a more resilient Digital Single Market.”
Reporting becomes part of product operations
Because the CRA applies horizontally to products with digital elements, the reporting requirement reaches well beyond conventional cybersecurity suppliers. Connected industrial equipment, enterprise software, operating systems, network products, smart devices, and many other technology categories can fall within the framework, shifting vulnerability reporting towards a standard operating obligation for companies that may never previously have regarded disclosure as a regulated process.
Technology supply chains will make the change particularly difficult. Commercial products routinely incorporate open-source components, third-party libraries, chipsets, cloud services, development frameworks, and other dependencies, which means a vulnerability originating elsewhere can still create obligations for the manufacturer placing the final product on the EU market.
Maintaining accurate component inventories and supplier relationships therefore becomes more valuable than a compliance exercise performed shortly before a product launches. When a widely used dependency is compromised, manufacturers need to establish quickly whether they are affected, which versions are exposed, which customers may be at risk, and whether the event crosses the threshold for formal reporting.
The reporting platform itself also becomes sensitive infrastructure. ENISA says it has implemented technical and organisational measures to protect information submitted through the service, which may include details of vulnerabilities that remain exploitable while organisations are still investigating or deploying fixes.
That creates a balance between sharing enough information for authorities to coordinate responses and avoiding unnecessary dissemination of technically sensitive material. The CRA allows notification handling to be delayed in particularly exceptional circumstances, but manufacturers still need processes capable of distinguishing those cases from ordinary reporting.
Open-source software stewards will eventually enter the same system, although their corresponding obligations apply from December 2027. Their inclusion reflects the central role open-source software plays throughout commercial technology products while recognising that open-source governance and resources often look very different from those of conventional manufacturers.
The next year will give ENISA, national authorities, and technology suppliers practical evidence about how the regime behaves before the CRA’s wider requirements take effect. Reporting volumes, incomplete notifications, classification disputes, cross-border incidents, and interactions between manufacturers and national CSIRTs will expose where the new machinery works cleanly and where guidance needs to evolve.
For companies selling digital products into the EU, however, one change is already settled. Product vulnerabilities can now create regulatory obligations while engineers are still diagnosing them, bringing legal reporting deadlines directly into vulnerability management rather than leaving cybersecurity disclosure to internal policy alone.












