CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

EU Cyber Resilience Act

policy · policy:eu-cyber-resilience-act single-sourcesingle-source-national-cert

EU product-security regulation; first hard deadline (designation of notifying authorities) fell on 11 June 2026, with the CRA Single Reporting Platform following on 11 September 2026. Tracked for its direct compliance impact on European software and hardware vendors.

Aliases: CRA

Coverage
4
first 2026-05-09 → last 2026-09-29
Latest activity
2026-09-26
Bern moves the critical-infrastructure breach-reporting duty into a new, standalone Cybersecurity Act
Peak priority
notable
4 notable
Targets
public-sector
sectors: public-sector, technology, energy · regions: europe, switzerland
Sources cited
12
8 hosts

Defender insights

What each entry about EU Cyber Resilience Act tells a defender to do, newest first.

2026-08-29NOTABLENCSC-FI supplies the CRA reporting deadlines the Commission's own guidance had left unstated

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

related to

Story timeline

  1. 2026-09-26Switzerland's Federal Council orders drafting of a standalone Cybersecurity Act (CSG), relocating the critical-infrastructure incident-reporting duty out of the Information Security Act
    researchBern moves the critical-infrastructure breach-reporting duty into a new, standalone Cybersecurity Act
  2. 2026-08-29Finland's NCSC-FI publishes an operational manufacturer checklist for the EU Cyber Resilience Act's 24h/72h/14-day/1-month reporting clock, two weeks before the 11 September 2026 go-live
    researchNCSC-FI supplies the CRA reporting deadlines the Commission's own guidance had left unstated
  3. 2026-06-10EU Cyber Resilience Act reaches its first hard deadline, notifying-authority designation due 11 June
    active-threats
  4. 2026-05-09ENISA expands CVE Root: four new European organisations onboarded as CVE Numbering Authorities
    research

Entries about EU Cyber Resilience Act (4)

2026-09-26 · view entry permalink →

NOTABLENATOA2

Switzerland's Federal Council orders drafting of a standalone Cybersecurity Act (CSG), relocating the critical-infrastructure incident-reporting duty out of the Information Security Act

Switzerland's Federal Council decided at its session of 2026-09-25 to task the Federal Department of Defence, Civil Protection and Sport (VBS) with drafting, by June 2027, a consultation proposal for a new, standalone federal Cybersecurity Act (Bundesgesetz über die Cybersicherheit, CSG) (Bundesamt für Cybersicherheit, 2026-09-25). The CSG folds together three previously separate parliamentary mandates the Federal Office for Cybersecurity (BACS) had been developing as amendments to the existing Information Security Act (ISG): binding cyber-resilience requirements for manufacturers, importers and retailers of hardware and software products, explicitly modeled on the EU Cyber Resilience Act to ease compliance for internationally active firms already subject to it; strengthened protection duties for particularly important digital data; and participation and defense obligations for hosting and cloud providers (Bundesamt für Cybersicherheit, 2026-09-25).

Most consequential for the constituency this brief serves: the existing mandatory cyber-incident reporting duty for critical-infrastructure operators, in effect under the ISG since April 2025, is being relocated out of the ISG and into the new CSG; the ISG itself will continue to govern only the information security of federal authorities (Bundesamt für Cybersicherheit, 2026-09-25). Sector-specific rules under the Telecommunications Act, the Electricity Supply Ordinance and the Telecommunications Installations Ordinance are left untouched, with the CSG framed as supplementing them with cross-cutting duties. No operational obligation changes today: this is a drafting mandate with a June 2027 consultation-draft deadline, not yet a bill, but it settles the future statutory home of the incident-reporting duty that federal, cantonal and communal critical-infrastructure operators already comply with, and signals that product-cyber-resilience and hosting/cloud-provider obligations comparable to the EU CRA are coming to Switzerland as a dedicated instrument rather than an ISG amendment.

"The Federal Council, at its session of 25 September 2026, tasked the Federal Department of Defence, Civil Protection and Sport (VBS), for the purpose of strengthening national cybersecurity, with drafting, by June 2027, a consultation proposal for a new, standalone federal Cybersecurity Act." # (translated from German)

"a standalone federal Cybersecurity Act (Cybersicherheitsgesetz, CSG) is to be created, into which the cyber-incident reporting duty for critical infrastructure operators, in effect under the ISG since April 2025, will also be transferred. The ISG will continue to govern the information security of federal authorities." # (translated from German)

"The Federal Council has tasked the VBS with drafting a consultation proposal by June 2027 and submitting it for decision." # (translated from German)

Bundesamt für Cybersicherheit (BACS) 2026-09-25
policy26 Sep 04:04Zsingle-source · national CERTOpen finding →

2026-08-29 · view entry permalink →

NOTABLEupdatedNATOA2

Finland's NCSC-FI publishes an operational manufacturer checklist for the EU Cyber Resilience Act's 24h/72h/14-day/1-month reporting clock, two weeks before the 11 September 2026 go-live

The EU Cyber Resilience Act's reporting obligations bind from 11 September 2026, requiring manufacturers of "products with digital elements" placed on the EU market to report actively exploited vulnerabilities and severe incidents through ENISA's centralised Single Reporting Platform (SRP) (NCSC-FI / Traficom, 2026-08-28). On 2026-08-28, with two weeks left before the obligation binds, NCSC-FI published a manufacturer checklist supplying the concrete notification clock: an early warning within 24 hours of the manufacturer becoming aware of an actively exploited vulnerability or severe incident, supplemented within 72 hours; for a vulnerability, a final report within 14 days after a corrective or mitigating measure becomes available; for a severe incident, a final report within one month of the incident notification (NCSC-FI / Traficom, 2026-08-28). ENISA's own FAQ for the platform independently states the identical clock (ENISA, 2026-08-31). The SRP became operational on 11 September 2026, the same date the reporting duty started to apply, and is reached at portal.cra-srp.enisa.europa.eu through a personal EU Login account with multi-factor authentication (ENISA, updated 2026-09-17). NCSC-FI's checklist directs manufacturers to identify in-scope products now, noting that products past end-of-life and no longer receiving updates remain subject to the reporting obligation, appoint an Assigned Representative (AR) authorised to submit SRP notifications, document an internal report-intake and triage process, and rehearse it at least once before the first reportable case (NCSC-FI / Traficom, 2026-08-28). ENISA's own FAQ states a manufacturer may register one Primary AR and up to 20 Secondary ARs, and that a representative whose manufacturer association is not yet verified may still submit up to 20 notifications for that manufacturer before verification becomes mandatory, so an organisation does not have to wait for verification to complete before filing its first report under time pressure (ENISA, updated 2026-09-17). NCSC-FI's own checklist instead describes notifications as submittable only through two named representatives, a narrower figure than ENISA's; the two authorities have not been reconciled, and ENISA's FAQ is treated as the more current statement of the platform's own rules (NCSC-FI / Traficom, 2026-08-28). API-based submission is not expected until spring 2027 per NCSC-FI, and ENISA's own FAQ states only that "no Application Programming Interface (API) will be provided at the initial release of the SRP" and that one may follow in a later phase, without a target date, so any automated vulnerability-management or SBOM-correlation pipeline still has to terminate at a manual web-portal boundary for every notification filed before that changes (NCSC-FI / Traficom, 2026-08-28; ENISA, 2026-08-31). The reporting duty is not limited to products launched after 11 September 2026: legal analysis of Article 69(3) CRA confirms it applies from that date to every in-scope product already placed on the EU market (Hogan Lovells Cadwalader, 2026-06-10), and NCSC-FI's own checklist states products past end-of-life and no longer receiving updates remain subject to the obligation regardless (NCSC-FI / Traficom, 2026-08-28).

For an actively exploited vulnerability or a severe incident, an early warning must be submitted within 24 hours of the manufacturer becoming aware of it. The notification must be supplemented within 72 hours.

For a vulnerability, the final report must be submitted within 14 days after a corrective or mitigating measure becomes available. For a severe incident, the final report must be submitted within one month of the incident notification.

Notifications are expected to be possible through APIs from spring 2027. After this, notifications can be submitted directly from the organisation's own system.

NCSC-FI / Traficom

The platform has become operational on 11 September 2026, coinciding with the date on which the CRA reporting obligations under Art.14 are applicable.

However, no Application Programming Interface (API) will be provided at the initial release of the SRP, so notifications must be submitted through the platform interface.

ARs whose manufacturer association has not yet been verified may submit up to 20 notifications for that manufacturer before verification becomes mandatory.

In the current release, the 72-hour counter displays a due date/time 48hrs after submission of the 24-hour Early Warning.

ENISA, Single Reporting Platform (SRP) FAQ 2026-08-31

Notably, the reporting obligations apply from 11 September 2026 to all products with digital elements within the CRA's scope that have been made available on the EU market before full CRA application (Art. 69(3) CRA).

Hogan Lovells Cadwalader

As of 11 September 2026, manufacturers are required to report actively exploited vulnerabilities and severe incidents impacting the security of products with digital elements.

ENISA has established the CRA Single Reporting Platform (SRP), operational as of 11 September 2026.

European Commission, Shaping Europe's Digital Future 2026-07-31

From 11 September 2026, manufacturers are required to submit these mandatory notifications through the SRP.

ENISA, Single Reporting Platform (SRP) page 2026-09-10

The EU Agency for Cybersecurity (ENISA) has deployed the initial operating capability of the Single Reporting Platform (SRP).

ENISA 2026-09-11

Der Bitkom kritisiert insbesondere, dass Unternehmen die Meldeplattform vor deren Start nicht registrieren und die Prozesse nicht erproben konnten. Die Plattform ging erst mit Beginn der Meldepflicht online. (translated from German: Bitkom specifically criticizes that companies could not register on the reporting platform or test their processes before its start. The platform only went online with the start of the reporting obligation.)

heise online (relaying a Bitkom survey finding)
Updaterun 2026-09-03T0410Z-intelsourcesevidencesourcing_notesummarybody

ENISA's own Single Reporting Platform FAQ, updated 31 August 2026, now independently states the same 24-hour/ 72-hour/14-day/1-month notification clock this entry previously sourced to NCSC-FI alone (ENISA, 2026-08-31). The Assigned Representative cap this entry previously described as "two" is corrected: ENISA's FAQ states a manufacturer may register exactly one Primary AR and up to 20 Secondary ARs, and that a non-validated AR can submit up to 20 notifications before validation becomes mandatory (ENISA, 2026-08-31). Eight days before the 11 September go-live, the platform still has no published URL and the FAQ confirms no API will exist at launch, without stating a specific date for one; the spring-2027 API target remains NCSC-FI's own claim, not independently corroborated (ENISA, 2026-08-31). Legal analysis of Article 69(3) CRA confirms the reporting duty applies from 11 September 2026 to every in-scope product already on the EU market (Hogan Lovells Cadwalader, 2026-06-10), consistent with NCSC-FI's own checklist, which states products past end-of-life and no longer receiving updates remain subject to the obligation regardless (NCSC-FI / Traficom, 2026-08-28). The SRP will be available in English only at launch (ENISA, Single Reporting Platform (SRP) FAQ, 2026-08-31).

Updaterun 2026-09-11T0410Z-intelsummarysourcing_notebodysourcesevidencetags

The obligation this entry has tracked ahead of go-live is now in legal effect: the European Commission's own page states plainly, "as of 11 September 2026, manufacturers are required to report actively exploited vulnerabilities and severe incidents impacting the security of products with digital elements" (European Commission, 2026-07-31). This covers every in-scope product already placed on the EU market before today, not only new ones, consistent with Article 69(3) CRA as this entry already recorded. Neither the Commission's page nor ENISA's own SRP page states that the platform is confirmed live and accepting submissions today; the Commission's page says only that "the Single Reporting Platform will be operational by 11 September 2026 (date of entry into application of the CRA reporting requirements)" and that "functional and security testing are under way" (European Commission, 2026-07-31), while ENISA's own SRP page states that "from 11 September 2026, manufacturers are required to submit these mandatory notifications through the SRP" without an explicit operational-status confirmation (ENISA, 2026-09-10). This entry therefore scopes its claim to what is independently confirmed (the legal reporting obligation is in effect) rather than to platform operational status, which no source reached has confirmed either way as of today.

Updaterun 2026-09-12T0409Z-intelsourcing_notesourcesevidencebody

The open point above is resolved: ENISA confirmed on 2026-09-11 that "the EU Agency for Cybersecurity (ENISA) has deployed the initial operating capability of the Single Reporting Platform (SRP)" (ENISA, 2026-09-11), manufacturers and, from 11 December 2027, open-source software stewards submit once through the platform and the receiving CSIRT disseminates the notification to every other Member State CSIRT where the affected product is available, simultaneously to ENISA. A Bitkom survey of 1,003 German firms, relayed the same day by heise online, found only 29% know what the CRA means for their own organization and a further 38% have heard of it but cannot assess the impact; Bitkom specifically criticizes that manufacturers could not register on the platform or test their reporting process before today, "because the platform only went online with the start of the reporting obligation" (translated from German) (heise online, 2026-09-11). For a Swiss manufacturer or distributor placing networked products on the EU market, or a Swiss public-sector body procuring from an EU-regulated manufacturer now subject to this clock, the practical takeaway is that the 24-hour/72-hour/14-day-or-1-month reporting chain is a live obligation rather than a target date, and a first submission may hit friction precisely because pre-launch registration and testing were not possible.

Improvementrun 2026-09-29T2134Z-auditevidencesourcing_notebody

The European Commission's own CRA reporting page now also confirms the launch: "ENISA has established the CRA Single Reporting Platform (SRP), operational as of 11 September 2026" (European Commission, updated 2026-09-11). The page previously gave 11 September 2026 as the target date with testing under way, which is the wording quoted in the 2026-09-11 section above.

ENISA's FAQ, revised on 17 September, now also answers the questions this entry left open before launch. The platform is at portal.cra-srp.enisa.europa.eu and each Assigned Representative signs in with a personal EU Login account with multi-factor authentication. No API exists at the initial release, and ENISA says only that one may be considered in a future phase. One operational detail matters for the reporting clock: "In the current release, the 72-hour counter displays a due date/time 48hrs after submission of the 24-hour Early Warning", so the platform can mark a notification overdue before 72 hours have passed since the manufacturer became aware. ENISA says a later release will count from the awareness time instead (ENISA, updated 2026-09-17).

policy29 Aug 04:09Zmulti-sourceOpen finding →

2026-06-10 · view entry permalink →

NOTABLE

EU Cyber Resilience Act reaches its first hard deadline, notifying-authority designation due 11 June

UPDATE (originally covered 2026-W23 weekly): 11 June 2026 is the CRA's first mandatory operational milestone: under Chapter IV, member states must have designated the national authority responsible for notifying conformity-assessment bodies (CABs) for higher-risk product classes (European Commission, 2026-06-10). This is the upstream gate for the September 2026 incident-reporting obligations (Article 14) and full CRA applicability in December 2027; manufacturers of Class II/III products can now begin engaging notified CABs.

No Commission communiqué naming specific member-state designations had been published as of this brief; the confirmed fact is the regulatory deadline itself. Public-sector procurement of connected devices is directly downstream of this milestone. [SINGLE-SOURCE]

threat10 Jun 05:00Zsingle-sourceOpen finding →

Earlier coverage (1)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Research3
  • Threats1

Source distribution

  • enisa.europa.eu4 (33%)
  • digital-strategy.ec.europa.eu2 (17%)
  • bacs.admin.ch1 (8%)
  • heise.de1 (8%)
  • hlc.com1 (8%)
  • kyberturvallisuuskeskus.fi1 (8%)
  • netzwoche.ch1 (8%)
  • swisscybersecurity.net1 (8%)
All cited sources (12)