Filing on the ENISA Single Reporting Platform

Every report under Article 14 goes through one platform, run by ENISA, which forwards it to the coordinating CSIRT.Art. 16 The platform is live at portal.cra-srp.enisa.europa.eu. This page lists what it asks for, in the order it asks, so the first time you see the form is not the first time you are filling it in.

Before the first report

A named person submits
Notifications are entered by an authorised representative signed in with EU Login and multi-factor authentication. A manufacturer registers one primary representative and up to twenty secondary ones. Set this up before you need it: the registration is not a step you want to discover at hour twenty-three.
There is no API
ENISA has confirmed the platform takes submissions through its web interface only. Any product that says it files on your behalf is describing something that does not exist. What a product can do is produce the packet a person transcribes.ENISA FAQ 15
Validation does not gate submission
A manufacturer can submit before its CSIRT has validated the registration; up to twenty notifications may be filed before verification becomes mandatory. The clock does not wait for a validation email, and neither should you.
Choosing the wrong CSIRT can void the notification
The coordinating CSIRT is fixed by Article 14(7), and a notification sent to the wrong one may be invalidated and have to be resubmitted. Work out which one is yours in advance.ENISA FAQ 18
English only, for now
The interface and the fields are in English at launch.ENISA FAQ 24
If the platform is down, wait
ENISA’s guidance is to submit when the platform returns. Contacting the CSIRT directly in the meantime is sensible and does not discharge the duty by itself.ENISA FAQ 25

The platform’s own 72-hour counter is currently wrong

ENISA states in its FAQ (entry 26) that the platform shows the 72-hour due time as 48 hours after the early warning was submitted, and that this will be corrected in a future release. The Regulation runs the 72 hours from when you became aware, not from when you submitted.Art. 14⁠(2)⁠⁠(b)⁠ Compute the deadline yourself, or use something that does; do not read it off the console.

The fields, stage by stage

Aligned to ENISA’s CRA SRP Glossary, Version 1.3, 10 September 2026. Each field carries the glossary row it comes from and the article it satisfies. Fields the platform does not have are marked; they are kept because the duty behind them is real and is discharged outside the form.

Early warning

Due within 24 hours of becoming aware. 7 required fields; the rest can be left for a later stage.

Notification

What kind of report this is, and a title the authority can recognise it by.

  • Notification type

    requiredplatform fillsone of: Vulnerability · Incident

  • Title

    requiredtext, up to 255 characters

    Short and specific enough to recognise the product and the issue, with no confidential technical detail. For example: "Active exploitation affecting Product X version 4.2".

  • Summary

    requiredfree text, up to 4,000 characters

    What happened, the affected product or version, the known impact, and the current mitigation status. Facts available at this stage; it is carried forward and can be updated at each later stage.

  • Considered sensitivity of this information

    text, up to 255 characters

    Say so where wider circulation would itself increase the risk to users. Not a generic confidentiality statement.

Manufacturer

The platform fills the manufacturer name from your registration. The rest is for your own record of the filing.

  • Legal entity name

    platform fillstext

    Shown by the platform as you registered it. Check it matches.

  • Registered address

    free text

    For your record. Not a platform field.

    Art. 14⁠(1)⁠not a platform field
  • EU establishment or authorised representative

    free text

    Relevant if you have no establishment in the Union. For your record; the platform takes this from registration.

    Art. 14⁠(7)⁠not a platform field
  • Point of contact

    text

    For your record. The platform uses the submitting representative’s own account.

    Art. 14⁠(1)⁠not a platform field
  • Contact email

    text

    For your record. Not a platform field.

    Art. 14⁠(1)⁠not a platform field
  • Contact telephone

    text

    For your record. Not a platform field.

    Art. 14⁠(1)⁠not a platform field

Product

  • Product name

    requiredtext, up to 255 characters

    The official product name.

  • Product version or version range

    requiredtext, up to 255 characters

    For example "4.0–4.2.1", or a single version.

  • Member states where the product is available

    requiredone or more

    Every member state where you know the product has been made available. The platform uses this to decide which national teams are concerned, and pre-selects the one you registered with.

  • Product type

    one of: Default · Important Product with Digital Elements · Critical Product with Digital Elements

    Choose Important or Critical only where the product falls within Annex III or IV; otherwise Default. This never changes a reporting deadline.

    Annex IIIglossary #8
  • Product class

    one of: Class I · Class II

    Leave empty unless the product is an important product.

    Annex IIIglossary #9
  • Product category

    one of: Identity management systems, and privileged access management software and hardware, including authentication and access control readers · Standalone and embedded browsers · Password managers · Software that searches for, removes or quarantines malicious software · Products with the function of a virtual private network (VPN) · Network management systems · Security information and event management (SIEM) systems · Boot managers · Public key infrastructure and digital certificate issuance software · Physical and virtual network interfaces · Operating systems · Routers, modems intended for connection to the internet, and switches · Microprocessors with security-related functionalities · Microcontrollers with security-related functionalities · ASICs and FPGAs with security-related functionalities · Smart home general purpose virtual assistants · Smart home products with security functionalities, including smart door locks, security cameras, baby monitors and alarm systems · Internet-connected toys with social interactive features or location tracking · Personal wearables with a health monitoring purpose outside the medical device regulations, or wearables intended for children · Hypervisors and container runtime systems supporting virtualised execution of operating systems · Firewalls, intrusion detection and prevention systems · Tamper-resistant microprocessors · Tamper-resistant microcontrollers · Hardware devices with security boxes · Smart meter gateways, and other devices for advanced security purposes including secure cryptoprocessing · Smartcards and similar devices, including secure elements

    The Annex III or IV category, where one applies.

    Annex IIIglossary #10
  • Is the product past its support period?

    one of: Yes · No

    Art. 13⁠(8)⁠glossary #11

Initial indication

The early warning is deliberately short. It exists to start the clock and tell the authority something is happening, not to be complete.

  • Date and time you became aware

    requireddate and time, shown in UTC

    When you first had reason to believe the product was affected. If the exact time is unknown, enter your best supported estimate and say so in the summary.

    Art. 14⁠(2)⁠⁠(a)⁠glossary v26 / i37

Notification

Due within 72 hours of becoming aware. 8 required fields; the rest can be left for a later stage.

Notification

What kind of report this is, and a title the authority can recognise it by.

  • Notification type

    requiredplatform fillsone of: Vulnerability · Incident

  • Title

    requiredtext, up to 255 characters

    Short and specific enough to recognise the product and the issue, with no confidential technical detail. For example: "Active exploitation affecting Product X version 4.2".

  • Summary

    requiredfree text, up to 4,000 characters

    What happened, the affected product or version, the known impact, and the current mitigation status. Facts available at this stage; it is carried forward and can be updated at each later stage.

  • Considered sensitivity of this information

    text, up to 255 characters

    Say so where wider circulation would itself increase the risk to users. Not a generic confidentiality statement.

Manufacturer

The platform fills the manufacturer name from your registration. The rest is for your own record of the filing.

  • Legal entity name

    platform fillstext

    Shown by the platform as you registered it. Check it matches.

  • Registered address

    free text

    For your record. Not a platform field.

    Art. 14⁠(1)⁠not a platform field
  • EU establishment or authorised representative

    free text

    Relevant if you have no establishment in the Union. For your record; the platform takes this from registration.

    Art. 14⁠(7)⁠not a platform field
  • Point of contact

    text

    For your record. The platform uses the submitting representative’s own account.

    Art. 14⁠(1)⁠not a platform field
  • Contact email

    text

    For your record. Not a platform field.

    Art. 14⁠(1)⁠not a platform field
  • Contact telephone

    text

    For your record. Not a platform field.

    Art. 14⁠(1)⁠not a platform field

Product

  • Product name

    requiredtext, up to 255 characters

    The official product name.

  • Product version or version range

    requiredtext, up to 255 characters

    For example "4.0–4.2.1", or a single version.

  • Member states where the product is available

    requiredone or more

    Every member state where you know the product has been made available. The platform uses this to decide which national teams are concerned, and pre-selects the one you registered with.

  • Product type

    one of: Default · Important Product with Digital Elements · Critical Product with Digital Elements

    Choose Important or Critical only where the product falls within Annex III or IV; otherwise Default. This never changes a reporting deadline.

    Annex IIIglossary #8
  • Product class

    one of: Class I · Class II

    Leave empty unless the product is an important product.

    Annex IIIglossary #9
  • Product category

    one of: Identity management systems, and privileged access management software and hardware, including authentication and access control readers · Standalone and embedded browsers · Password managers · Software that searches for, removes or quarantines malicious software · Products with the function of a virtual private network (VPN) · Network management systems · Security information and event management (SIEM) systems · Boot managers · Public key infrastructure and digital certificate issuance software · Physical and virtual network interfaces · Operating systems · Routers, modems intended for connection to the internet, and switches · Microprocessors with security-related functionalities · Microcontrollers with security-related functionalities · ASICs and FPGAs with security-related functionalities · Smart home general purpose virtual assistants · Smart home products with security functionalities, including smart door locks, security cameras, baby monitors and alarm systems · Internet-connected toys with social interactive features or location tracking · Personal wearables with a health monitoring purpose outside the medical device regulations, or wearables intended for children · Hypervisors and container runtime systems supporting virtualised execution of operating systems · Firewalls, intrusion detection and prevention systems · Tamper-resistant microprocessors · Tamper-resistant microcontrollers · Hardware devices with security boxes · Smart meter gateways, and other devices for advanced security purposes including secure cryptoprocessing · Smartcards and similar devices, including secure elements

    The Annex III or IV category, where one applies.

    Annex IIIglossary #10
  • Is the product past its support period?

    one of: Yes · No

    Art. 13⁠(8)⁠glossary #11

When

Nature of the vulnerability or incident

Initial assessment

Corrective and mitigating measures

  • Corrective or mitigating measures taken

    free text, up to 2,000 characters

    Actions already taken. Required in full at the final report.

  • Corrective or mitigating measures users can take

    free text, up to 4,000 characters

    Required in full at the final report.

  • User action able to reduce impact

    free text, up to 4,000 characters

  • Is a mitigating measure expected shortly?

    one of: Yes · No

  • Have users been informed, and how?

    free text

    For your record. The platform has no field for this; the duty is real and is met outside it.

    Art. 14⁠(8)⁠not a platform field

Particular exceptional circumstances

Optional, vulnerabilities only, and only at this stage. Invoking it means ENISA receives partial information until the receiving CSIRT makes the full notification available. The three grounds are quoted from the delegated act.

Final report

Due within 14 days of a fix being available, or one month after the incident notification. 13 required fields; the rest can be left for a later stage.

Notification

What kind of report this is, and a title the authority can recognise it by.

  • Notification type

    requiredplatform fillsone of: Vulnerability · Incident

  • Title

    requiredtext, up to 255 characters

    Short and specific enough to recognise the product and the issue, with no confidential technical detail. For example: "Active exploitation affecting Product X version 4.2".

  • Summary

    requiredfree text, up to 4,000 characters

    What happened, the affected product or version, the known impact, and the current mitigation status. Facts available at this stage; it is carried forward and can be updated at each later stage.

  • Considered sensitivity of this information

    text, up to 255 characters

    Say so where wider circulation would itself increase the risk to users. Not a generic confidentiality statement.

Manufacturer

The platform fills the manufacturer name from your registration. The rest is for your own record of the filing.

  • Legal entity name

    platform fillstext

    Shown by the platform as you registered it. Check it matches.

  • Registered address

    free text

    For your record. Not a platform field.

    Art. 14⁠(1)⁠not a platform field
  • EU establishment or authorised representative

    free text

    Relevant if you have no establishment in the Union. For your record; the platform takes this from registration.

    Art. 14⁠(7)⁠not a platform field
  • Point of contact

    text

    For your record. The platform uses the submitting representative’s own account.

    Art. 14⁠(1)⁠not a platform field
  • Contact email

    text

    For your record. Not a platform field.

    Art. 14⁠(1)⁠not a platform field
  • Contact telephone

    text

    For your record. Not a platform field.

    Art. 14⁠(1)⁠not a platform field

Product

  • Product name

    requiredtext, up to 255 characters

    The official product name.

  • Product version or version range

    requiredtext, up to 255 characters

    For example "4.0–4.2.1", or a single version.

  • Member states where the product is available

    requiredone or more

    Every member state where you know the product has been made available. The platform uses this to decide which national teams are concerned, and pre-selects the one you registered with.

  • Product type

    one of: Default · Important Product with Digital Elements · Critical Product with Digital Elements

    Choose Important or Critical only where the product falls within Annex III or IV; otherwise Default. This never changes a reporting deadline.

    Annex IIIglossary #8
  • Product class

    one of: Class I · Class II

    Leave empty unless the product is an important product.

    Annex IIIglossary #9
  • Product category

    one of: Identity management systems, and privileged access management software and hardware, including authentication and access control readers · Standalone and embedded browsers · Password managers · Software that searches for, removes or quarantines malicious software · Products with the function of a virtual private network (VPN) · Network management systems · Security information and event management (SIEM) systems · Boot managers · Public key infrastructure and digital certificate issuance software · Physical and virtual network interfaces · Operating systems · Routers, modems intended for connection to the internet, and switches · Microprocessors with security-related functionalities · Microcontrollers with security-related functionalities · ASICs and FPGAs with security-related functionalities · Smart home general purpose virtual assistants · Smart home products with security functionalities, including smart door locks, security cameras, baby monitors and alarm systems · Internet-connected toys with social interactive features or location tracking · Personal wearables with a health monitoring purpose outside the medical device regulations, or wearables intended for children · Hypervisors and container runtime systems supporting virtualised execution of operating systems · Firewalls, intrusion detection and prevention systems · Tamper-resistant microprocessors · Tamper-resistant microcontrollers · Hardware devices with security boxes · Smart meter gateways, and other devices for advanced security purposes including secure cryptoprocessing · Smartcards and similar devices, including secure elements

    The Annex III or IV category, where one applies.

    Annex IIIglossary #10
  • Is the product past its support period?

    one of: Yes · No

    Art. 13⁠(8)⁠glossary #11

When

Detailed description

  • Full description of the severity

    requiredfree text, up to 4,000 characters

    Art. 14⁠(2)⁠⁠(c)⁠glossary v24 / i34
  • Full description of the impact

    requiredfree text, up to 4,000 characters

    The affected systems, components, data, users or services, as applicable.

    Art. 14⁠(2)⁠⁠(c)⁠glossary v25 / i35
  • Information on the malicious actor

    text, up to 100 characters

    Required by the platform if such information is available. Observed indicators, or a statement that attribution is unknown.

Corrective and mitigating measures

  • Corrective or mitigating measures taken

    requiredfree text, up to 2,000 characters

  • Corrective or mitigating measures users can take

    requiredfree text, up to 4,000 characters

  • Details of the security update or corrective measure available

    requiredfree text, up to 2,000 characters

  • Lessons learned and process changes

    free text

    For your record, not a platform field — and worth writing: it is the part a market-surveillance authority reads as evidence of a working process.

    Art. 14⁠(2)⁠⁠(c)⁠not a platform field

Exceptional circumstances

At the 72-hour notification, and only for a vulnerability, a manufacturer may ask that ENISA receive partial information until the coordinating CSIRT makes the full notification available. The three grounds are set by delegated act, and the platform quotes them verbatim; so does the guide above. It is not a way to delay the report.Art. 16⁠(2)⁠

The packet, filled from what you already know

Declara produces each of the three stages from these same definitions, pre-filled from your product and the advisory, with the clocks computed from awareness. You transcribe it; nothing files for you.

Registration and the platform itself are ENISA’s. Their FAQ is the source for the facts above and is updated more often than this page.

This produces evidence, timelines and drafts. It is not legal advice, and you remain the party responsible for reporting.