Fwd: CRA reporting, SRP & ENISA advisory

From: Alice Sowerby <alice_at_freebsdfoundation.org>
Date: Tue, 22 Sep 2026 07:57:57 UTC
Please note:

Mandatory reporting of actively exploited vulnerabilities and severe
[security] incidents is now in force within the EU. This applies to
manufacturers who are currently selling PDE (products with digital
elements) in the EU. It does not apply to open source projects directly.

Please find below a correspondence from the European Commission which
explains the change.

I would be happy to help with any questions on this subject.

Alice.

---------- Forwarded message ---------
From: CNECT-CRA@ec.europa.eu <CNECT-CRA@ec.europa.eu>
Date: Thu, 17 Sept 2026 at 17:32
Subject: CRA reporting, SRP & ENISA advisory
To: CNECT-CRA@ec.europa.eu <CNECT-CRA@ec.europa.eu>


Dear CRA Network,



Please find below some updates of relevance for the implementation of the
CRA.



*Entry into application of CRA reporting obligations & ENISA Single
Reporting Platform*

On 11 September 2026, reporting obligations pursuant to Article 14 of the
CRA entered into application. To this end, ENISA – working in close
cooperation with the CSIRT Network - launched the CRA Single Reporting
Platform. All the information about the SRP, including user guidance, FAQs,
and training materials are available at this link: Single Reporting
Platform (SRP) | ENISA
<https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp>.
We would like to warmly thank ENISA for the work that went into this
endeavour.



In line with ENISA’s advice
<https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/cra-srp-guidance-ar-user-registration>,
manufacturers are advised to register on the CRA SRP only when they need to
submit a specific notification, rather than registering pre-emptively.
Pre-registration is not a prerequisite for submitting a notification.



Further clarifications on reporting obligations are also contained in
Section 9.1 of the Commission guidance
<https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation>
on
the CRA, as well as in Section 5 of the Commission's Frequently Asked
Questions <https://ec.europa.eu/newsroom/dae/redirection/document/122331> on
the CRA implementation. The Commission webpage on reporting
<https://digital-strategy.ec.europa.eu/en/policies/cra-reporting> has also
been updated accordingly. We draw your attention in particular to the
following clarification, added in FAQ 5.5:



*5.5 Are open-source software stewards subject to reporting obligations
under the CRA? *

*Article 24(3) of the CRA establishes that reporting obligations laid down
in Article 14, paragraphs (1), (3) and (8), apply to open-source software
stewards under certain circumstances. In accordance with Article 71(2) of
the CRA, Article 24(3) shall apply from 11 December 2027.*





*ENISA’s Draft Technical Advisory on AI-assisted software development*

ENISA published for public consultation a draft Technical Advisory on
AI-assisted software development
<https://www.enisa.europa.eu/sites/default/files/2026-09/ENISA%20Technical%20Advisory-AI-assisted-software-development-draft.pdf>:
as they put it, AI-assisted software development is becoming standard
practice, but functional code should not be confused with secure code.
ENISA’s advisory also includes an agentic skill
<https://github.com/enisaeu/agentic-skills> to help AI assistants make
safer decisions when recommending, installing, updating, reviewing, or
managing software packages and dependencies.

Please do not hesitate to provide feedback
<https://www.linkedin.com/safety/go/?url=https%3A%2F%2Flnkd.in%2FdaqxNDEv&urlhash=O3cf&mt=607LETTBXCefBs6fdppKKavdJlAw6D1HJ7dkd2dJCMoC2uHJoLqoQyiJli6qpVvk-_tGFN-o7JRIkbM6laEBymIsy7NYz-TdGz8lD3GNA_ip7qCfcofoGsMriQ&isSdui=true&lipi=urn%3Ali%3Apage%3Ad_flagship3_search_srp_all%3B6OA8bG%2F0TJScQpvZYPDvDw%3D%3D>
to ENISA. Deadline: 15 October 2026.



Best wishes,

CRA Team



*Have you been forwarded this email? Sign up here
<https://urldefense.com/v3/__https:/ec.europa.eu/eusurvey/runner/CRA-implementation__;!!O7_YSHcmd9jp3hj_4dEAcyQ!1WpaMYGJJ8h2AJbR81y6VDBdXx5wmVhJgXgyG5mJ144ftQxO9EIoQTo8T0UzM1GQ0lnWjY0M99v7QCYxUAI_E3A$>.
*

*You no longer wish to receive these updates? Please reply to this email
and we will delete you from our database.*
_______________________________________________
open-regulatory-compliance mailing list
open-regulatory-compliance@eclipse.org
To unsubscribe from this list, visit https://accounts.eclipse.org