CRA Reporting Copilot / Guides
ENISA's Single Reporting Platform: what is settled, what isn't, and how to prepare before 11 September 2026
July 2026 · 5 min read · reflects public information as of early July 2026
When the Cyber Resilience Act's reporting duty applies on 11 September 2026, manufacturers will not be choosing where to send their Article 14 reports case by case. Regulation (EU) 2024/2847 establishes, in Article 16, a single reporting platform set up and maintained by ENISA — one submission that reaches both the coordinating CSIRT and ENISA. For teams building their reporting process now, the practical question is what can be relied on today versus what is still moving. The honest answer has three layers.
Settled: what the regulation itself fixes
- The mechanism exists by law. Art. 16(1) tasks ENISA with establishing the platform; the single-entry-point model — report once, reach the coordinating CSIRT and ENISA — is the regulation's design, not a proposal.
- The timeline. The Article 14 reporting obligations apply from 11 September 2026 (Art. 71(2)). This date is fixed in the regulation.
- The staged content structure. What each stage must convey — early warning within 24 hours, notification within 72 hours, final report with its two path-dependent start points — is written into Art. 14 and does not depend on the platform's implementation details.
Published: what ENISA has put out
ENISA has published an overview of the reporting data items per stage — which fields are expected at the early-warning, notification, and final-report stages, with markings distinguishing mandatory, optional, conditional, and known-at-the-time items. This is the most useful artifact currently available for template building: it lets you structure your internal drafts so the facts are already organised the way the platform expects to receive them. ENISA has also begun providing preparatory material for manufacturers ahead of the go-live, with a testing period planned before the platform takes real reports.
Being finalized: what not to hard-code
The registration procedure — how a manufacturer gets an account, what identity information is required — and the exact submission forms are still being finalized as of this writing. Two practical consequences:
- Don't build automation against an interface that isn't stable. Any tooling or internal process that hard-codes a submission form today is building on sand. The resilient posture for 2026 is export-and-submit: your process produces a complete, well-structured draft, and a human submits it through the official channel in whatever form that channel takes at go-live.
- Assign someone to watch. Registration details, form specifics, and test-period logistics will land in ENISA's public materials in the run-up to September. A recurring calendar slot — even biweekly — to check ENISA's platform pages and the European Commission's CRA reporting page costs fifteen minutes and prevents a scramble.
How to prepare without waiting
| Do now | Why it's safe to do now |
| Structure internal draft templates around ENISA's published per-stage data items | The data items are public; the structure survives form changes |
| Fix the two final-report start points in your runbook (14 days after a measure is available / one month after the 72-hour submission) | Written in Art. 14(2)(c) and 14(4)(c); platform-independent |
| Prepare the affected-user and upstream-component notices alongside | Art. 14(8) and Art. 13(6) duties do not run through the platform's forms |
| Rehearse the flow once, ending at "export the draft" | The human-submits step is the part that won't change |
| Register / complete onboarding | When the procedure is published — watch ENISA's pages |
This is the posture CRA Reporting Copilot is built around: templates aligned to the published per-stage data items, designed to be updated as the platform's format lands; drafts exported as PDF/JSON for a human to submit; nothing auto-filed. The readiness check is free:
overview ·
documentation.
Sources: Regulation (EU) 2024/2847 (Cyber Resilience Act), Art. 14, 16(1), 71(2) — EUR-Lex; ENISA, Single Reporting Platform pages (enisa.europa.eu); European Commission, "Cyber Resilience Act — Reporting obligations" (digital-strategy.ec.europa.eu). Status statements reflect public information as of early July 2026; verify current status on the official pages.