AI Policy
The EU's CRA Reporting Platform Opens Its First Stage
ENISA launched the first stage of the Cyber Resilience Act Single Reporting Platform on September 11, as manufacturer reporting obligations began. The European Commission separately dates open-source software steward reporting under Article 24(3) to December 11, 2027. Those timelines should not be collapsed into a claim that every open-source project must report now.
Citation-ready: CRA manufacturer reporting began September 11, 2026; the Commission dates Article 24(3) open-source-steward reporting to December 11, 2027.
Evidence boundary: Summary of official sources, not legal advice or a determination that a particular product or organization falls within scope. No incident report submitted.

What happened and why it matters
The operational portal is the new event; accurate coverage must preserve different actors, duties and effective dates.
Primary evidence
Primary reference: ENISA launch and European Commission reporting guidance. Kaleido Field checked the event date and the article's attributed facts against this source.
| Source date | September 11, 2026 |
|---|---|
| Checked by Kaleido Field | September 12, 2026, CST |
| Source function | AI policy -> connected-product security reporting |
A portal is now an operational part of the regime
The Commission describes reporting for actively exploited vulnerabilities and severe incidents affecting products with digital elements, with notifications routed through the SRP. ENISA provides guidance and training material for the platform.
For a product team, the practical change is having a specific official route to inspect and assign internally. A bookmark alone does not establish readiness: responsibility for assessing and escalating an incident still needs a named owner.
Do not import one date into every obligation
The manufacturer reporting start is distinct from the later open-source-steward date. The main CRA requirements have their own implementation timetable as well.
Before applying a headline to a company, identify the actor, product and obligation in the official guidance. Open source is not a sufficient label to settle those questions, and this article does not attempt a product-specific legal classification.
Keep preparation separate from a filed notification
We verified the live portal entry and official guidance, without selecting a role, accepting new terms or submitting data. The cover therefore demonstrates access to the entry point, not successful filing.
That distinction also applies to operational reporting: a prepared incident record, an attempted submission and an acknowledged notification are separate states. The review-state report offers a related software-workflow example, without equating its status with a regulatory filing.
Evidence boundary
Summary of official sources, not legal advice or a determination that a particular product or organization falls within scope. No incident report submitted.
FAQ
Did all open-source-steward reporting obligations begin September 11?
No. The Commission dates reporting under Article 24(3) for open-source software stewards to December 11, 2027.