From 11 September 2026, a company that makes software sold in the European Union has to report certain security problems to the authorities — starting with an alert within 24 hours. The 24-hour form asks for far less than most teams assume, and that is the single most useful thing to know about it.
The harder part is not the form. It is the account you need in order to reach the form, and there are five mechanics in that process that will cost a team a morning if they meet them for the first time on the day something is actually on fire.
A note on terms first. The law is the Cyber Resilience Act — Regulation (EU) 2024/2847 — and it governs products with digital elements sold in the EU. A CSIRT is a Computer Security Incident Response Team: the national body that receives security reports in a given member state. ENISA is the EU agency for cybersecurity, and it operates the Single Reporting Platform, the one place these reports are filed.
Who this falls on, and from when
The duty in Article 14 falls on the manufacturer — the party that places a product on the EU market and monetises it. Territory of establishment does not matter; making the product available on the EU market does.
Three boundaries are worth stating plainly, because they are where most of the confusion sits:
- Free and open-source software that its own maker does not monetise is not treated as placed on the market commercially, and falls outside manufacturer obligations. The decisive test is monetisation, not licence. Receiving sponsorship or contributions does not cross the line; selling does.
- Open-source software stewards — typically foundations that sustain software used in commercial products — are a separate, lighter category with reduced duties.
- Software delivered purely as a cloud service is generally not a “product placed on the market” here at all. Those providers are addressed by NIS2 rather than by product law.
There is no size threshold. A small company that sells software in the EU is inside the duty on the same date as a large one.
Three stages, three clocks
The reporting duty is not one report. It is a cascade, and each stage has a different question behind it.
Two things about that picture are easy to get wrong. The windows run from awareness, not from confirmation or from having a fix — so the 24-hour clock can start on a Friday evening with an incomplete picture, which is exactly why the first form is short. And the report is filed once: the platform routes it to the CSIRT designated as coordinator in the member state of the manufacturer’s main establishment, and to ENISA.
The 24-hour form is an alert, not an investigation
This is the finding that changes how you prepare. The mandatory set at 24 hours is six fields, and none of them requires analysis you would not already have at the moment you became aware.
The submission form additionally asks for the product type — default, important or critical — and, where it is not default, the relevant Annex III or IV category. That one is worth settling in advance rather than in the first hour, because it is a classification question and not a factual one.
The mechanics that will actually cost you time
The form is the easy part. The account is not. Five things about registration are worth knowing before you need them.
Accounts run through EU Login. That account can be created today and involves no CSIRT.
There are two seats: a primary representative and a backup. The primary invites the backup by email, and that invitation expires after seven days. An unaccepted invitation leaves the backup with no role at all.
Do not register on the platform early. ENISA has explicitly asked manufacturers not to, because every registration creates validation work for the national CSIRTs. The middle path ENISA’s own FAQ permits is the sensible one: create the EU Login account now, leave platform registration until you need it. And note that validation by the coordinating CSIRT is not a prerequisite for meeting the obligation — it runs in parallel and does not block a submission.
An unverified account can file only ten notifications. This is the first quantified limit ENISA has published, and it comes with real unknowns: the guidance does not say what happens at the eleventh attempt, whether the ceiling counts events or submissions, or precisely which association it attaches to.
Your backup cannot see your drafts. The dashboard shows only drafts created by the logged-in user; drafts are private to their author. If the person who started a report is unreachable, the work is not visible to the colleague covering for them — and the 24-hour clock does not pause for that.
One smaller operational point with an easy fix: platform confirmations and alerts go to all registered representatives, not only the person who submitted. Point them at a monitored mailbox rather than an individual.
A naming trap worth catching before it reaches a procedure
ENISA’s guidance is written around the assigned representative — recently renamed in the interface to AR Primary User and AR Backup User. That is a platform account role: who may log in and file.
It is not the authorised representative under Article 18, which is a legal appointment relevant where a manufacturer is established outside the EU.
A company can have one and not the other. The two are a single abbreviation apart, and if that abbreviation makes it into an internal procedure without a definition, someone will eventually read the wrong obligation into it. Write both out in full, once, and the trap closes.
What was still missing in late August
As of the last check against ENISA’s own pages in late August 2026 — the guidance is explicitly marked subject to change, and had already been revised twice since it first appeared — three things had not yet appeared:
| Still missing | What it means for you |
|---|---|
| The platform’s public address | The guidance screenshots still carried “URL to be provided at launch.” |
| The list of national CSIRTs designated as coordinators | Awkward, because registration asks you to pick yours from a list. |
| Any submission API | ENISA states none will be provided at this stage. |
On the second of those: the underlying question — where is our main establishment, and if it is outside the EU, where is our Article 18 representative established — does not depend on the list being published, and can be answered today. On the third: internal workflow can be automated right up to submission, but at launch a human types the final entry into a browser.
ENISA has signalled short videos and a webinar roughly two weeks before go-live.
Sensitivity does not pause the clock
A manufacturer can flag the conditions in Article 16(2) to restrict who sees the content of a report. The decision on onward dissemination then belongs to the receiving CSIRT, under Commission Delegated Regulation (EU) 2026/881.
What that mechanism restricts is content, not timing. The windows still run from awareness. And there is a second-order consequence worth planning around: concerned CSIRTs in other member states receive the early warning, the 72-hour notification and the final report only after manual dissemination by the coordinating CSIRT. ENISA still receives the early warning automatically. No legal duty changed there, but a human at one national CSIRT now sits between a report and the rest of the Union.
What to have ready before 11 September
None of this needs a project. It needs about an hour and two named people.
- Name a primary and a backup representative — and send the backup's invitation with more than seven days in hand, not on the day you need them.
- Create the EU Login account now; leave the platform registration itself until you need it, as ENISA asks.
- Answer, in writing, where your main establishment is — and, if it is outside the EU, where your Article 18 authorised representative is established. That determines which CSIRT coordinates for you, whether or not the list is published.
- Route platform notifications to a monitored mailbox rather than to one person's inbox.
- Write a one-page internal decision path: who declares awareness, who files, and what the fallback is when the person holding the draft is unreachable.
The honest summary
The 11 September duty is smaller than its reputation and more procedural than most teams expect. The first report asks six questions, the analysis is due two days later, and the substance of the thing is a staged disclosure rather than a same-day investigation.
Where it will hurt is the plumbing: an account nobody set up, an invitation that expired, a draft only one person can see, and a list of coordinating CSIRTs that was not published in time to look yours up calmly. The first three are fixable this week. The fourth is ENISA’s to publish — but the question underneath it, where your main establishment is, you can answer today without them. None of the four is fixable at hour twenty-three.
Frequently asked questions
Who has to report from 11 September 2026?
The duty in Article 14 falls on manufacturers — in the Act's sense, the party that places a product with digital elements on the EU market and monetises it — regardless of where that party is established. Free and open-source software that its own maker does not monetise is not treated as placed on the market commercially and falls outside manufacturer obligations; a lighter regime exists for open-source software stewards, typically foundations. Software delivered purely as a cloud service is generally not a product placed on the market under this Regulation and is addressed by NIS2 instead. Whether any of that describes your situation is a question for your own counsel.
What exactly does the 24-hour report have to contain?
Six things: the notification type, the notification level, the name of the manufacturer or steward, the product concerned, a title, and — for incidents — whether unlawful or malicious acts are suspected. That is the whole mandatory set. Nature of the vulnerability, nature of the exploit and corrective measures become mandatory at the 72-hour stage, and full description, severity, impact and security-update detail at the final report. The submission form also asks for the product type (default, important or critical) and, where it is not default, the relevant Annex III or IV category.
Should I register on the ENISA platform now?
ENISA has asked manufacturers not to register early, because every registration creates validation work for the national CSIRTs. The workable middle path, which ENISA's own FAQ permits: create the EU Login account now — that involves no CSIRT at all — and leave platform registration until you need it. Note also that validation of a registration by the coordinating CSIRT is not a prerequisite for meeting the reporting obligation; it runs in parallel and does not block submission.
Is ENISA's “assigned representative” the same as an authorised representative under Article 18?
No, and this is the most common mistake. ENISA's assigned representative (also written as AR Primary User and AR Backup User) is a platform account role — who may log in and file. The authorised representative under Article 18 is a legal appointment, relevant where a manufacturer is established outside the EU. A company can have one and not the other. If your internal procedure uses the phrase without saying which it means, fix that before September.
Can I delay a report if the vulnerability is sensitive?
No — sensitivity does not pause the clock. A manufacturer can flag the conditions in Article 16(2) to restrict who sees the content, and the decision on onward dissemination then belongs to the receiving CSIRT under Commission Delegated Regulation (EU) 2026/881. But that restricts content, not timing: the 24-hour, 72-hour and final-report windows run from awareness, and nothing pauses them. Not legal advice.
Sources & further reading
- Regulation (EU) 2024/2847 — the Cyber Resilience Act (EUR-Lex) — the Regulation itself; Article 14 is the reporting duty, Article 16(2) dissemination, Article 18 the authorised representative
- ENISA — Single Reporting Platform — the platform hub, and the parent of the guidance pages below
- ENISA — SRP guidance: assigned representative user registration — EU Login, the primary and backup roles, and the seven-day invitation expiry
- ENISA — SRP guidance: assigned representative interface functions — account states, the ten-notification ceiling for unverified accounts, and what the dashboard does and does not show
- ENISA — Single Reporting Platform: frequently asked questions — including the guidance on when to register
- Commission Delegated Regulation (EU) 2026/881 — the conditions under which a CSIRT may delay onward dissemination of a report
- European Commission — CRA reporting obligations — the Commission's own overview of the duty