Filing on the ENISA Single Reporting Platform
Every report under Article 14 goes through one platform, run by ENISA, which forwards it to the coordinating CSIRT.Art. 16 The platform is live at portal.cra-srp.enisa.europa.eu. This page lists what it asks for, in the order it asks, so the first time you see the form is not the first time you are filling it in.
Before the first report
- A named person submits
- Notifications are entered by an authorised representative signed in with EU Login and multi-factor authentication. A manufacturer registers one primary representative and up to twenty secondary ones. Set this up before you need it: the registration is not a step you want to discover at hour twenty-three.
- There is no API
- ENISA has confirmed the platform takes submissions through its web interface only. Any product that says it files on your behalf is describing something that does not exist. What a product can do is produce the packet a person transcribes.ENISA FAQ 15
- Validation does not gate submission
- A manufacturer can submit before its CSIRT has validated the registration; up to twenty notifications may be filed before verification becomes mandatory. The clock does not wait for a validation email, and neither should you.
- Choosing the wrong CSIRT can void the notification
- The coordinating CSIRT is fixed by Article 14(7), and a notification sent to the wrong one may be invalidated and have to be resubmitted. Work out which one is yours in advance.ENISA FAQ 18
- English only, for now
- The interface and the fields are in English at launch.ENISA FAQ 24
- If the platform is down, wait
- ENISA’s guidance is to submit when the platform returns. Contacting the CSIRT directly in the meantime is sensible and does not discharge the duty by itself.ENISA FAQ 25
The platform’s own 72-hour counter is currently wrong
ENISA states in its FAQ (entry 26) that the platform shows the 72-hour due time as 48 hours after the early warning was submitted, and that this will be corrected in a future release. The Regulation runs the 72 hours from when you became aware, not from when you submitted.Art. 14(2)(b) Compute the deadline yourself, or use something that does; do not read it off the console.
The fields, stage by stage
Aligned to ENISA’s CRA SRP Glossary, Version 1.3, 10 September 2026. Each field carries the glossary row it comes from and the article it satisfies. Fields the platform does not have are marked; they are kept because the duty behind them is real and is discharged outside the form.
Early warning
Due within 24 hours of becoming aware. 7 required fields; the rest can be left for a later stage.
Notification
What kind of report this is, and a title the authority can recognise it by.
Notification type
requiredplatform fillsone of: Vulnerability · Incident
Art. 14(1)glossary #1Title
requiredtext, up to 255 characters
Short and specific enough to recognise the product and the issue, with no confidential technical detail. For example: "Active exploitation affecting Product X version 4.2".
Art. 14(2)(a)glossary #2Summary
requiredfree text, up to 4,000 characters
What happened, the affected product or version, the known impact, and the current mitigation status. Facts available at this stage; it is carried forward and can be updated at each later stage.
Art. 14(2)(a)glossary #3Considered sensitivity of this information
text, up to 255 characters
Say so where wider circulation would itself increase the risk to users. Not a generic confidentiality statement.
Art. 14(2)(b)glossary #15
Manufacturer
The platform fills the manufacturer name from your registration. The rest is for your own record of the filing.
Legal entity name
platform fillstext
Shown by the platform as you registered it. Check it matches.
Art. 14(1)glossary #4Registered address
free text
For your record. Not a platform field.
Art. 14(1)not a platform fieldEU establishment or authorised representative
free text
Relevant if you have no establishment in the Union. For your record; the platform takes this from registration.
Art. 14(7)not a platform fieldPoint of contact
text
For your record. The platform uses the submitting representative’s own account.
Art. 14(1)not a platform fieldContact email
text
For your record. Not a platform field.
Art. 14(1)not a platform fieldContact telephone
text
For your record. Not a platform field.
Art. 14(1)not a platform field
Product
Product name
requiredtext, up to 255 characters
The official product name.
Art. 14(2)(b)glossary #6Product version or version range
requiredtext, up to 255 characters
For example "4.0–4.2.1", or a single version.
Art. 14(2)(b)glossary #7Member states where the product is available
requiredone or more
Every member state where you know the product has been made available. The platform uses this to decide which national teams are concerned, and pre-selects the one you registered with.
Art. 14(2)(a)glossary #5Product type
one of: Default · Important Product with Digital Elements · Critical Product with Digital Elements
Choose Important or Critical only where the product falls within Annex III or IV; otherwise Default. This never changes a reporting deadline.
Annex IIIglossary #8Product class
one of: Class I · Class II
Leave empty unless the product is an important product.
Annex IIIglossary #9Product category
one of: Identity management systems, and privileged access management software and hardware, including authentication and access control readers · Standalone and embedded browsers · Password managers · Software that searches for, removes or quarantines malicious software · Products with the function of a virtual private network (VPN) · Network management systems · Security information and event management (SIEM) systems · Boot managers · Public key infrastructure and digital certificate issuance software · Physical and virtual network interfaces · Operating systems · Routers, modems intended for connection to the internet, and switches · Microprocessors with security-related functionalities · Microcontrollers with security-related functionalities · ASICs and FPGAs with security-related functionalities · Smart home general purpose virtual assistants · Smart home products with security functionalities, including smart door locks, security cameras, baby monitors and alarm systems · Internet-connected toys with social interactive features or location tracking · Personal wearables with a health monitoring purpose outside the medical device regulations, or wearables intended for children · Hypervisors and container runtime systems supporting virtualised execution of operating systems · Firewalls, intrusion detection and prevention systems · Tamper-resistant microprocessors · Tamper-resistant microcontrollers · Hardware devices with security boxes · Smart meter gateways, and other devices for advanced security purposes including secure cryptoprocessing · Smartcards and similar devices, including secure elements
The Annex III or IV category, where one applies.
Annex IIIglossary #10Is the product past its support period?
one of: Yes · No
Art. 13(8)glossary #11
Initial indication
The early warning is deliberately short. It exists to start the clock and tell the authority something is happening, not to be complete.
Date and time you became aware
requireddate and time, shown in UTC
When you first had reason to believe the product was affected. If the exact time is unknown, enter your best supported estimate and say so in the summary.
Art. 14(2)(a)glossary v26 / i37
Notification
Due within 72 hours of becoming aware. 8 required fields; the rest can be left for a later stage.
Notification
What kind of report this is, and a title the authority can recognise it by.
Notification type
requiredplatform fillsone of: Vulnerability · Incident
Art. 14(1)glossary #1Title
requiredtext, up to 255 characters
Short and specific enough to recognise the product and the issue, with no confidential technical detail. For example: "Active exploitation affecting Product X version 4.2".
Art. 14(2)(a)glossary #2Summary
requiredfree text, up to 4,000 characters
What happened, the affected product or version, the known impact, and the current mitigation status. Facts available at this stage; it is carried forward and can be updated at each later stage.
Art. 14(2)(a)glossary #3Considered sensitivity of this information
text, up to 255 characters
Say so where wider circulation would itself increase the risk to users. Not a generic confidentiality statement.
Art. 14(2)(b)glossary #15
Manufacturer
The platform fills the manufacturer name from your registration. The rest is for your own record of the filing.
Legal entity name
platform fillstext
Shown by the platform as you registered it. Check it matches.
Art. 14(1)glossary #4Registered address
free text
For your record. Not a platform field.
Art. 14(1)not a platform fieldEU establishment or authorised representative
free text
Relevant if you have no establishment in the Union. For your record; the platform takes this from registration.
Art. 14(7)not a platform fieldPoint of contact
text
For your record. The platform uses the submitting representative’s own account.
Art. 14(1)not a platform fieldContact email
text
For your record. Not a platform field.
Art. 14(1)not a platform fieldContact telephone
text
For your record. Not a platform field.
Art. 14(1)not a platform field
Product
Product name
requiredtext, up to 255 characters
The official product name.
Art. 14(2)(b)glossary #6Product version or version range
requiredtext, up to 255 characters
For example "4.0–4.2.1", or a single version.
Art. 14(2)(b)glossary #7Member states where the product is available
requiredone or more
Every member state where you know the product has been made available. The platform uses this to decide which national teams are concerned, and pre-selects the one you registered with.
Art. 14(2)(a)glossary #5Product type
one of: Default · Important Product with Digital Elements · Critical Product with Digital Elements
Choose Important or Critical only where the product falls within Annex III or IV; otherwise Default. This never changes a reporting deadline.
Annex IIIglossary #8Product class
one of: Class I · Class II
Leave empty unless the product is an important product.
Annex IIIglossary #9Product category
one of: Identity management systems, and privileged access management software and hardware, including authentication and access control readers · Standalone and embedded browsers · Password managers · Software that searches for, removes or quarantines malicious software · Products with the function of a virtual private network (VPN) · Network management systems · Security information and event management (SIEM) systems · Boot managers · Public key infrastructure and digital certificate issuance software · Physical and virtual network interfaces · Operating systems · Routers, modems intended for connection to the internet, and switches · Microprocessors with security-related functionalities · Microcontrollers with security-related functionalities · ASICs and FPGAs with security-related functionalities · Smart home general purpose virtual assistants · Smart home products with security functionalities, including smart door locks, security cameras, baby monitors and alarm systems · Internet-connected toys with social interactive features or location tracking · Personal wearables with a health monitoring purpose outside the medical device regulations, or wearables intended for children · Hypervisors and container runtime systems supporting virtualised execution of operating systems · Firewalls, intrusion detection and prevention systems · Tamper-resistant microprocessors · Tamper-resistant microcontrollers · Hardware devices with security boxes · Smart meter gateways, and other devices for advanced security purposes including secure cryptoprocessing · Smartcards and similar devices, including secure elements
The Annex III or IV category, where one applies.
Annex IIIglossary #10Is the product past its support period?
one of: Yes · No
Art. 13(8)glossary #11
When
Date and time you became aware
requireddate and time, shown in UTC
Art. 14(2)(b)glossary v26 / i37
Nature of the vulnerability or incident
CVE identifier
text, up to 255 characters
Art. 14(2)(b)glossary v19EUVD identifier
text, up to 255 characters
The record in the European Vulnerability Database, if one exists.
Art. 14(2)(b)glossary v20Component name
text, up to 255 characters
Art. 14(2)(b)glossary #12Weakness type (CWE)
text
For your record. Not a platform field.
Art. 14(2)(b)not a platform fieldAttack vector
text, up to 255 characters
Art. 14(2)(b)glossary #18General information about the vulnerability or incident
requiredfree text, up to 4,000 characters
The nature of the exploit or the incident, as understood at seventy-two hours.
Art. 14(2)(b)glossary v21 / i32
Initial assessment
Severity (CVSS)
text
For your record. Not a platform field.
Art. 14(2)(b)not a platform fieldImpact
free text, up to 4,000 characters
What is known so far. Required in full at the final report.
Art. 14(2)(b)glossary v25 / i35Number and type of users affected, if known
free text
For your record. Not a platform field.
Art. 14(2)(b)not a platform field
Corrective and mitigating measures
Corrective or mitigating measures taken
free text, up to 2,000 characters
Actions already taken. Required in full at the final report.
Art. 14(2)(b)glossary #16Corrective or mitigating measures users can take
free text, up to 4,000 characters
Required in full at the final report.
Art. 14(2)(b)glossary #17User action able to reduce impact
free text, up to 4,000 characters
Art. 14(2)(b)glossary #14Is a mitigating measure expected shortly?
one of: Yes · No
Art. 14(2)(b)glossary #13Have users been informed, and how?
free text
For your record. The platform has no field for this; the duty is real and is met outside it.
Art. 14(8)not a platform field
Particular exceptional circumstances
Optional, vulnerabilities only, and only at this stage. Invoking it means ENISA receives partial information until the receiving CSIRT makes the full notification available. The three grounds are quoted from the delegated act.
Grounds relied on
any that apply
Art. 16(2)glossary v28 / v29Further information
free text, up to 800 characters
Art. 16(2)glossary v30
Final report
Due within 14 days of a fix being available, or one month after the incident notification. 13 required fields; the rest can be left for a later stage.
Notification
What kind of report this is, and a title the authority can recognise it by.
Notification type
requiredplatform fillsone of: Vulnerability · Incident
Art. 14(1)glossary #1Title
requiredtext, up to 255 characters
Short and specific enough to recognise the product and the issue, with no confidential technical detail. For example: "Active exploitation affecting Product X version 4.2".
Art. 14(2)(a)glossary #2Summary
requiredfree text, up to 4,000 characters
What happened, the affected product or version, the known impact, and the current mitigation status. Facts available at this stage; it is carried forward and can be updated at each later stage.
Art. 14(2)(a)glossary #3Considered sensitivity of this information
text, up to 255 characters
Say so where wider circulation would itself increase the risk to users. Not a generic confidentiality statement.
Art. 14(2)(b)glossary #15
Manufacturer
The platform fills the manufacturer name from your registration. The rest is for your own record of the filing.
Legal entity name
platform fillstext
Shown by the platform as you registered it. Check it matches.
Art. 14(1)glossary #4Registered address
free text
For your record. Not a platform field.
Art. 14(1)not a platform fieldEU establishment or authorised representative
free text
Relevant if you have no establishment in the Union. For your record; the platform takes this from registration.
Art. 14(7)not a platform fieldPoint of contact
text
For your record. The platform uses the submitting representative’s own account.
Art. 14(1)not a platform fieldContact email
text
For your record. Not a platform field.
Art. 14(1)not a platform fieldContact telephone
text
For your record. Not a platform field.
Art. 14(1)not a platform field
Product
Product name
requiredtext, up to 255 characters
The official product name.
Art. 14(2)(b)glossary #6Product version or version range
requiredtext, up to 255 characters
For example "4.0–4.2.1", or a single version.
Art. 14(2)(b)glossary #7Member states where the product is available
requiredone or more
Every member state where you know the product has been made available. The platform uses this to decide which national teams are concerned, and pre-selects the one you registered with.
Art. 14(2)(a)glossary #5Product type
one of: Default · Important Product with Digital Elements · Critical Product with Digital Elements
Choose Important or Critical only where the product falls within Annex III or IV; otherwise Default. This never changes a reporting deadline.
Annex IIIglossary #8Product class
one of: Class I · Class II
Leave empty unless the product is an important product.
Annex IIIglossary #9Product category
one of: Identity management systems, and privileged access management software and hardware, including authentication and access control readers · Standalone and embedded browsers · Password managers · Software that searches for, removes or quarantines malicious software · Products with the function of a virtual private network (VPN) · Network management systems · Security information and event management (SIEM) systems · Boot managers · Public key infrastructure and digital certificate issuance software · Physical and virtual network interfaces · Operating systems · Routers, modems intended for connection to the internet, and switches · Microprocessors with security-related functionalities · Microcontrollers with security-related functionalities · ASICs and FPGAs with security-related functionalities · Smart home general purpose virtual assistants · Smart home products with security functionalities, including smart door locks, security cameras, baby monitors and alarm systems · Internet-connected toys with social interactive features or location tracking · Personal wearables with a health monitoring purpose outside the medical device regulations, or wearables intended for children · Hypervisors and container runtime systems supporting virtualised execution of operating systems · Firewalls, intrusion detection and prevention systems · Tamper-resistant microprocessors · Tamper-resistant microcontrollers · Hardware devices with security boxes · Smart meter gateways, and other devices for advanced security purposes including secure cryptoprocessing · Smartcards and similar devices, including secure elements
The Annex III or IV category, where one applies.
Annex IIIglossary #10Is the product past its support period?
one of: Yes · No
Art. 13(8)glossary #11
When
Date and time you became aware
requireddate and time, shown in UTC
Art. 14(2)(c)glossary v26 / i37Date and time a corrective or mitigating measure became available
requireddate and time, shown in UTC
Art. 14(2)(c)glossary v22
Detailed description
Full description of the severity
requiredfree text, up to 4,000 characters
Art. 14(2)(c)glossary v24 / i34Full description of the impact
requiredfree text, up to 4,000 characters
The affected systems, components, data, users or services, as applicable.
Art. 14(2)(c)glossary v25 / i35Information on the malicious actor
text, up to 100 characters
Required by the platform if such information is available. Observed indicators, or a statement that attribution is unknown.
Art. 14(2)(c)glossary v27
Corrective and mitigating measures
Corrective or mitigating measures taken
requiredfree text, up to 2,000 characters
Art. 14(2)(c)glossary #16Corrective or mitigating measures users can take
requiredfree text, up to 4,000 characters
Art. 14(2)(c)glossary #17Details of the security update or corrective measure available
requiredfree text, up to 2,000 characters
Art. 14(2)(c)glossary v23Lessons learned and process changes
free text
For your record, not a platform field — and worth writing: it is the part a market-surveillance authority reads as evidence of a working process.
Art. 14(2)(c)not a platform field
Exceptional circumstances
At the 72-hour notification, and only for a vulnerability, a manufacturer may ask that ENISA receive partial information until the coordinating CSIRT makes the full notification available. The three grounds are set by delegated act, and the platform quotes them verbatim; so does the guide above. It is not a way to delay the report.Art. 16(2)
The packet, filled from what you already know
Declara produces each of the three stages from these same definitions, pre-filled from your product and the advisory, with the clocks computed from awareness. You transcribe it; nothing files for you.
Registration and the platform itself are ENISA’s. Their FAQ is the source for the facts above and is updated more often than this page.
This produces evidence, timelines and drafts. It is not legal advice, and you remain the party responsible for reporting.