CRA: Guide to Reporting via the SRP

by SPAC Alliance | September 2026 | Cyber Resilience Act, Library, Regulations

Since 11 September 2026, manufacturers have been required to report actively exploited vulnerabilities and severe incidents affecting the security of their products with digital elements, in accordance with Article 14 of the Cyber Resilience Act (CRA). These reports must be submitted through the Single Reporting Platform (SRP), established under Article 16 and developed and operated by ENISA.

To support manufacturers, ENISA has published the CRA SRP – AR User Manual, a practical guide for individuals designated to submit reports on their behalf, known as Assigned Representatives (ARs).

What does the manual cover?

The manual follows the user journey through five sections, with step-by-step instructions and screenshots:

  • Introduction: platform scope, intended users and definitions.
  • User registration: registering a Primary AR, linking their account to a manufacturer and inviting Secondary ARs.
  • Login and logout: accessing the platform.
  • Platform workflows: managing user roles and linking user accounts to manufacturers, using the dashboard, submitting early warnings within 24 hours of becoming aware of an actively exploited vulnerability or severe incident, completing 72-hour notifications and final reports, updating notifications, and monitoring reminders and alerts.
  • Frequently asked questions: answers to common user queries.

A practical resource to help access control manufacturers within the scope of the CRA organise their reporting processes and get started with the platform.

SRP Useful links