The CRA reporting duty starts on Friday. The address to file at was published in a FAQ, and does not answer.
ENISA put the platform URL in a frequently asked questions page over the weekend with no announcement. Its own registration guidance, updated the same day, still says the address will be provided at launch.
By Parminder Kumar Sharma · · 9 min read

The Cyber Resilience Act's reporting duty starts on Friday 11 September 2026. The European Commission states it plainly on its own Cyber Resilience Act page: the main obligations apply from 11 December 2027, "with reporting obligations to apply as of 11 September 2026".
From Friday, a manufacturer that becomes aware of an actively exploited vulnerability in a product with digital elements has 24 hours to file an early warning, 72 hours for a fuller notification, and 14 days for a final report.
We wrote last week that the platform to file into was late. This is not that piece. This is what is actually in place three days out, each line checked against a primary source this afternoon rather than against coverage.
Three days out: what exists to report with
The address exists in one document and not in the other
The go-live address is now public. ENISA's SRP FAQ, stamped 8 September, gives it:
“The SRP will be available at https://portal.cra-srp.enisa.europa.eu. From there, select ‘Assigned Representative’ and log in using your EU Login account. The portal will be available from 11 September 2026.”
There was no announcement. No news item, no press release, nothing in the Official Journal. It appeared inside a frequently asked questions page, which grew from 23 questions to 30 over the weekend and now carries [NEW] and [UPDATED] markers for the first time: three new, five updated.
Now read the other document. ENISA's step-by-step registration guidance for authorised representatives, updated the same day, still opens step one like this:
“Open the SRP website (URL to be provided at launch)…”
The address appears nowhere in it. A manufacturer following the numbered instructions ENISA wrote for exactly this purpose cannot reach the portal the FAQ describes. Both pages are current. Both are ENISA's.
Two ENISA documents, retrieved the same afternoon
| ENISA document | State on 8 September 2026 | What it says about the address |
|---|---|---|
| Single Reporting Platform FAQ | Stamped 8 September 2026. Grew from 23 to 30 questions, with three “NEW” and five “UPDATED” markers. | “The SRP will be available at https://portal.cra-srp.enisa.europa.eu” |
| Authorised representative registration guidance | Updated the same day. | “Open the SRP website (URL to be provided at launch)…” |
The portal is not serving
We measured it at 17:05 UTC today.
The name resolves. portal.cra-srp.enisa.europa.eu is a CNAME to portal.cra-srp.enisa.europa.eu.wedos.global, which answers with 185.8.236.7 and 185.8.236.8. That is Wedos, a Czech commercial hosting provider, and not the delivery path www.enisa.europa.eu itself uses. A nonsense control subdomain returns NXDOMAIN on two independent resolvers, so this is a real record rather than a wildcard.
TCP connects in about 40 milliseconds. Then nothing: the TLS handshake never completes, and no HTTP response returns at either a 15 or a 45 second timeout.
The delegation to a commercial host outside the EU institutions' own infrastructure is a fair question to put to ENISA. It is not a finding, and we are not presenting it as one.
Three obligations that appeared over a weekend
The FAQ did not merely grow. Three of its new answers place work on manufacturers that was not there in the previous version, all within 72 hours of the duty starting.
You now pick the CSIRT, and picking wrong may void the filing. Verbatim: “If the wrong CDaC is selected, the notification may be invalidated and will need to be resubmitted to the correct CDaC.” The August version of the FAQ said the platform routes reports automatically. That burden has moved onto the filer, inside a 24-hour clock, and for a manufacturer selling across the single market the correct coordinator is not always obvious.
Filing without validation is capped at twenty. Verbatim: “Non-validated ARs may submit up to 20 notifications for one manufacturer before validation becomes mandatory.” That cap appears in the FAQ and in no version of the registration guidance.
Testing has stopped. Verbatim: “ENISA does not currently foresee additional testing before go-live.”
What is not there at all
There is no machine-readable format. We checked for JSON, XSD, XML and CSV and found none. The de facto specification is a glossary listing eighteen fields across the 24-hour, 72-hour and final stages.
There is no implementing act prescribing one, and none in preparation. Article 14(10) permits the Commission to specify the format by implementing act. It is a discretionary “may”, it carries no deadline, and it has not been used.
There is no API at launch. Notifications go through the platform interface. In practice a person retypes an incident into a web form, in English, which is the only language available at launch, inside 24 hours of becoming aware of it.
Voluntary reporting under Article 15 is not implemented at go-live; the FAQ places it in a future phase.
What to do before Friday
Take this with you
Practical steps, in the order they matter
- Register your authorised representative now, not during your first incident. It needs an EU Login account with multi-factor authentication enabled, and validation is a separate step from registration.
- Work out which national CSIRT is your coordinator, and write it down. Selecting the wrong one may invalidate the notification and force a resubmission inside a 24-hour window.
- Put the platform-unavailable case in your runbook. The regulation contains no provision stopping the clock, so decide now what you do and what you record if the portal does not answer when you need it.
- Keep your own record of the moment you became aware. That timestamp starts every clock in Article 14 and, on the current platform, is not yet a required field.
- Do not build an integration. There is no API and no published schema, so anything you build now is against an interface that has not been specified.
- Expect English. There is no other language at launch, so whoever files needs to be able to describe an incident precisely in it, at speed.
- If you are in the United Kingdom and sell into the EU, this applies to you through your EU-facing obligations. The NCSC has never published guidance on the Cyber Resilience Act, so do not wait for it.
The position
Regulators are entitled to ship a platform on the day the law says. Nobody is owed an early launch.
What is harder to defend is the manner of it. The address for discharging a legal duty was published inside a FAQ, on a Sunday, with no announcement, while the guidance written to walk people through that exact process still tells them the address will be provided later. Three new obligations landed in the same edit, one of which can void a filing made inside a 24-hour clock. Testing is finished. There is no schema, no implementing act and no API.
None of that changes the duty. On Friday the clock starts whether or not the portal answers, and the manufacturer carries the consequence of a missed deadline, not the platform.
Sources
- PrimaryENISA's Single Reporting Platform FAQ, stamped 8 September 2026, publishing the go-live address, the wrong-coordinator invalidation, the 20-notification cap for non-validated authorised representatives and the statement that no further testing is foreseen before go-liveENISAaccessed 2026-09-08
- PrimaryENISA's authorised representative registration guidance, updated the same day, whose first step still reads 'Open the SRP website (URL to be provided at launch)' and which does not contain the addressENISAaccessed 2026-09-08
- PrimaryThe Commission's Cyber Resilience Act page, stating that reporting obligations apply as of 11 September 2026 and main obligations from 11 December 2027European Commissionaccessed 2026-09-08


