• ENISA says its Cyber Resilience Act reporting platform will launch on 11 September without an API for automated submissions
  • Manufacturers can automate internal workflows, but a representative must still submit qualifying reports through the platform interface

The fact

ENISA has confirmed that the initial version of its Cyber Resilience Act Single Reporting Platform will not provide an API for automated submissions. Its guidance says organisations may automate their internal reporting workflows, but notifications must initially be filed through the platform interface.

The platform is scheduled to become operational on 11 September, when the CRA's mandatory reporting requirements begin. Manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements. An early warning is due without undue delay and within 24 hours of awareness, followed by a fuller notification within 72 hours.

Representatives submit reports using the platform and select the relevant national CSIRT designated as coordinator. ENISA says validation of a representative's association with a manufacturer takes place alongside the reporting process and does not initially prevent submission. The reporting obligations start before most of the CRA's wider product requirements, which become applicable in December 2027.

The Assessment

Manufacturers can automate how they detect an incident and collect the information needed for a CRA report, but that automation stops before the final submission. At launch, someone still has to open ENISA's platform and file the notification.

That makes the handover between a company's security systems and its reporting team important. Once a qualifying event is recognised, the 24-hour deadline is already running. Waiting for a complete investigation or finished patch could leave too little time for the first notification, which is designed to accept less information than the later stages.

For BTW readers, companies need to know who takes over when an internal alert becomes a reportable CRA event. That person needs access to the platform and enough coverage to submit within the deadline, including when an incident is discovered outside normal working hours. Automation can prepare the report, but it cannot submit it at launch.

What to watch

Watch the 11 September launch for any access, registration or submission problems as manufacturers begin using the platform. ENISA may later add an API, which would allow companies to automate more of the process. Until then, the practical checks are whether assigned representatives can access the system, submit on time and receive confirmation that the report was accepted.