AI Policy

The EU's CRA Reporting Platform Opens Its First Stage

By Kaleido Field Staff ยท September 12, 2026

The reporting start has a defined actor and scope

ENISA launched the first stage of the Cyber Resilience Act Single Reporting Platform on September 11, as manufacturer reporting obligations began. The European Commission separately dates open-source software steward reporting under Article 24(3) to December 11, 2027. Those timelines should not be collapsed into a claim that every open-source project must report now.

Citation-ready: CRA manufacturer reporting began September 11, 2026; the Commission dates Article 24(3) open-source-steward reporting to December 11, 2027.

Evidence boundary: Summary of official sources, not legal advice or a determination that a particular product or organization falls within scope. No incident report submitted.

ENISA Single Reporting Platform entry screen showing platform roles
Image source: ENISA; live portal entry captured September 12, with no role selected or notification submitted. Used for editorial coverage of product security regulation desk.

What happened and why it matters

The operational portal is the new event; accurate coverage must preserve different actors, duties and effective dates.

Primary evidence

Primary reference: ENISA launch and European Commission reporting guidance. Kaleido Field checked the event date and the article's attributed facts against this source.

Source check
Source dateSeptember 11, 2026
Checked by Kaleido FieldSeptember 12, 2026, CST
Source functionAI policy -> connected-product security reporting

A portal is now an operational part of the regime

The Commission describes reporting for actively exploited vulnerabilities and severe incidents affecting products with digital elements, with notifications routed through the SRP. ENISA provides guidance and training material for the platform.

For a product team, the practical change is having a specific official route to inspect and assign internally. A bookmark alone does not establish readiness: responsibility for assessing and escalating an incident still needs a named owner.

Do not import one date into every obligation

The manufacturer reporting start is distinct from the later open-source-steward date. The main CRA requirements have their own implementation timetable as well.

Before applying a headline to a company, identify the actor, product and obligation in the official guidance. Open source is not a sufficient label to settle those questions, and this article does not attempt a product-specific legal classification.

Keep preparation separate from a filed notification

We verified the live portal entry and official guidance, without selecting a role, accepting new terms or submitting data. The cover therefore demonstrates access to the entry point, not successful filing.

That distinction also applies to operational reporting: a prepared incident record, an attempted submission and an acknowledged notification are separate states. The review-state report offers a related software-workflow example, without equating its status with a regulatory filing.

Evidence boundary

Summary of official sources, not legal advice or a determination that a particular product or organization falls within scope. No incident report submitted.

Reader briefing

Keep the source trail in view.

One concise email when a model, benchmark, or visual-intelligence claim materially changes.

FAQ

Did all open-source-steward reporting obligations begin September 11?

No. The Commission dates reporting under Article 24(3) for open-source software stewards to December 11, 2027.