ENISA Launches CRA Single Reporting Platform for Actively Exploited Vulnerabilities
The European Union Agency for Cybersecurity (ENISA) has launched the Cyber Resilience Act's (CRA) Single Reporting Platform for actively exploited vulnerabilities. This platform, mandated by Article 16(1) of the CRA, enables manufacturers to report vulnerabilities and severe incidents. The platform went live on September 11, 2026, marking the start of binding reporting obligations for manufacturers placing products with digital elements on the EU market. Organizations must now report actively exploited vulnerabilities through this portal.