Resources
>
Blog
>
How should manufacturers prepare for CRA vulnerability and incident reporting through the ENISA Single Reporting Platform, and can it currently be automated?

How should manufacturers prepare for CRA vulnerability and incident reporting through the ENISA Single Reporting Platform, and can it currently be automated?

How should manufacturers prepare for CRA vulnerability and incident reporting through the ENISA Single Reporting Platform, and can it currently be automated?
TablE of contents

READY TO UPGRADE YOUR RISK MANAGEMENT?

Make cybersecurity and compliance efficient and effective with ONEKEY.

Book a Demo

Introduction and Regulatory Framework

From 11 September 2026, manufacturers of products with digital elements must comply with the Cyber Resilience Act (CRA) reporting obligations for certain cybersecurity events. This regulatory shift represents one of the most comprehensive overhauls of hardware and software security standards in European Union history, placing legally binding obligations directly on technology vendors, device fabricators, and software developers operating in the EU market.

The ENISA Single Reporting Platform (SRP) is the central online system for reporting:

• actively exploited vulnerabilities, and

• severe security incidents affecting products with digital elements.

Reporting is required when a manufacturer becomes aware of an actively exploited vulnerability in its product or a severe security incident affecting the product’s security.

Under the Cyber Resilience Act, the definition of a product with digital elements spans a vast range of connected devices, standalone software, and embedded hardware components. Consequently, manufacturers cannot treat these requirements as isolated IT concerns; rather, they require end-to-end integration across product design, quality assurance, field engineering, and legal compliance functions.

Strict Reporting Timelines and Multi-Stage Workflows

The reporting process is time-critical:

within 24 hours: an early warning must be submitted;

within 72 hours: a more detailed vulnerability or incident notification must follow;

• a final report is required later, once further investigation and remediation information is available.

Understanding the exact expectations for each phase is essential for establishing operational readiness:

1. The 24-Hour Early Warning: This initial notification is meant to alert ENISA and national Computer Security Incident Response Teams (CSIRTs) of a potential systemic threat. It must indicate whether the vulnerability or incident is believed to be caused by malicious intent and whether it poses a cross-border threat within the EU market.

2. The 72-Hour Detailed Notification: Building upon the early warning, this submission must provide a deeper technical analysis, including initial assessments of impact, severity scores (such as CVSS), and temporary mitigation steps recommended to users.

3. The Final Comprehensive Report: Submitted within one month of the incident or vulnerability remediation, this report must include a detailed root-cause analysis, a permanent patch or software update description, and corrective measures implemented to prevent recurrence.

Current Operational Status of the ENISA SRP

What is the current status of the ENISA SRP? As of 3 September 2026, ENISA states that the SRP is scheduled to become operational by 11 September 2026.

ENISA has already published guidance covering user registration, notification submission and the SRP workflow. However, the final public production URL has not yet been published.

Manufacturers should already prepare their internal reporting processes, responsibilities and EU Login access before the reporting obligation becomes applicable.

Waiting for the production portal to go live before establishing internal protocols carries immense risk. Because 24 hours leaves zero room for administrative overhead, legal reviews, or role clarification during a live emergency, companies must conduct tabletop exercises and dry-run simulations well in advance of September 2026.

Automation Capabilities and Technical Limitations

Can CRA reporting be automated? Only partly. ENISA currently does not provide an API for the SRP. This means that external platforms cannot automatically submit CRA notifications directly into the ENISA system.

This lack of a public Application Programming Interface (API) presents a notable hurdle for organizations striving for end-to-end security orchestration. Modern Security Operations Centers (SOCs) rely heavily on automated ticketing and response pipelines; however, for ENISA SRP compliance, a human-in-the-loop requirement remains unavoidable for the final transmission.

However, much of the preparation can still be automated. ONEKEY can help manufacturers:

  • identify relevant vulnerabilities,
  • correlate them with affected products and components,
  • collect and structure technical evidence, and
  • prepare the information required for the 24-hour and 72-hour notifications.

By automating Software Bill of Materials (SBOM) management, automated binary analysis, and continuous monitoring, automated security analysis platforms can drastically reduce the time needed to synthesize complex engineering data into standardized regulatory formats.

The actual submission to the ENISA SRP must currently still be completed manually by an authorised user.

Strategic Roadmap for Manufacturers

To ensure full compliance by the 11 September 2026 deadline, manufacturers should execute a structured five-step readiness plan:

  1. Inventory and SBOM Mapping: Maintain an accurate, up-to-date Software Bill of Materials for all connected products and embedded systems.
  2. Incident Response Triage Integration: Upgrade internal triage workflows so that security researchers and engineers automatically flag active exploitation triggers.
  3. Credential and Access Management: Establish authorized corporate EU Login accounts for designated primary and deputy compliance officers.
  4. Pre-Formatted Template Library: Pre-draft templates for 24-hour and 72-hour filings to minimize manual typing during high-stress incident windows.
  5. Continuous Monitoring and Automation Tools: Implement automated vulnerability correlation platforms to drastically compress data gathering timelines.
Share

About Onekey

ONEKEY is the leading European specialist in Product Cybersecurity & Compliance Management and part of the investment portfolio of PricewaterhouseCoopers Germany (PwC). The unique combination of the automated ONEKEY Product Cybersecurity & Compliance Platform (OCP) with expert knowledge and consulting services provides fast and comprehensive analysis, support, and management to improve product cybersecurity and compliance from product purchasing, design, development, production to end-of-life.

CONTACT:
Sara Fortmann

Senior Marketing Manager
sara.fortmann@onekey.com

euromarcom public relations GmbH
team@euromarcom.de

RELATED BLOG POST

The AI Vulnerability Storm Is Here. Embedded Manufacturers Need VulnOps.
Beyond the Hype: LLMs, Mythos, and the Future of Firmware Analysis
Vulnerability Management Framework: How to Meet CRA & NIS2 Requirements Efficiently

Make cybersecurity and compliance efficient and effective with ONEKEY.