Fwd: CRA reporting, SRP & ENISA advisory
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Tue, 22 Sep 2026 07:57:57 UTC
Please note: Mandatory reporting of actively exploited vulnerabilities and severe [security] incidents is now in force within the EU. This applies to manufacturers who are currently selling PDE (products with digital elements) in the EU. It does not apply to open source projects directly. Please find below a correspondence from the European Commission which explains the change. I would be happy to help with any questions on this subject. Alice. ---------- Forwarded message --------- From: CNECT-CRA@ec.europa.eu <CNECT-CRA@ec.europa.eu> Date: Thu, 17 Sept 2026 at 17:32 Subject: CRA reporting, SRP & ENISA advisory To: CNECT-CRA@ec.europa.eu <CNECT-CRA@ec.europa.eu> Dear CRA Network, Please find below some updates of relevance for the implementation of the CRA. *Entry into application of CRA reporting obligations & ENISA Single Reporting Platform* On 11 September 2026, reporting obligations pursuant to Article 14 of the CRA entered into application. To this end, ENISA – working in close cooperation with the CSIRT Network - launched the CRA Single Reporting Platform. All the information about the SRP, including user guidance, FAQs, and training materials are available at this link: Single Reporting Platform (SRP) | ENISA <https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp>. We would like to warmly thank ENISA for the work that went into this endeavour. In line with ENISA’s advice <https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/cra-srp-guidance-ar-user-registration>, manufacturers are advised to register on the CRA SRP only when they need to submit a specific notification, rather than registering pre-emptively. Pre-registration is not a prerequisite for submitting a notification. Further clarifications on reporting obligations are also contained in Section 9.1 of the Commission guidance <https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation> on the CRA, as well as in Section 5 of the Commission's Frequently Asked Questions <https://ec.europa.eu/newsroom/dae/redirection/document/122331> on the CRA implementation. The Commission webpage on reporting <https://digital-strategy.ec.europa.eu/en/policies/cra-reporting> has also been updated accordingly. We draw your attention in particular to the following clarification, added in FAQ 5.5: *5.5 Are open-source software stewards subject to reporting obligations under the CRA? * *Article 24(3) of the CRA establishes that reporting obligations laid down in Article 14, paragraphs (1), (3) and (8), apply to open-source software stewards under certain circumstances. In accordance with Article 71(2) of the CRA, Article 24(3) shall apply from 11 December 2027.* *ENISA’s Draft Technical Advisory on AI-assisted software development* ENISA published for public consultation a draft Technical Advisory on AI-assisted software development <https://www.enisa.europa.eu/sites/default/files/2026-09/ENISA%20Technical%20Advisory-AI-assisted-software-development-draft.pdf>: as they put it, AI-assisted software development is becoming standard practice, but functional code should not be confused with secure code. ENISA’s advisory also includes an agentic skill <https://github.com/enisaeu/agentic-skills> to help AI assistants make safer decisions when recommending, installing, updating, reviewing, or managing software packages and dependencies. Please do not hesitate to provide feedback <https://www.linkedin.com/safety/go/?url=https%3A%2F%2Flnkd.in%2FdaqxNDEv&urlhash=O3cf&mt=607LETTBXCefBs6fdppKKavdJlAw6D1HJ7dkd2dJCMoC2uHJoLqoQyiJli6qpVvk-_tGFN-o7JRIkbM6laEBymIsy7NYz-TdGz8lD3GNA_ip7qCfcofoGsMriQ&isSdui=true&lipi=urn%3Ali%3Apage%3Ad_flagship3_search_srp_all%3B6OA8bG%2F0TJScQpvZYPDvDw%3D%3D> to ENISA. Deadline: 15 October 2026. Best wishes, CRA Team *Have you been forwarded this email? Sign up here <https://urldefense.com/v3/__https:/ec.europa.eu/eusurvey/runner/CRA-implementation__;!!O7_YSHcmd9jp3hj_4dEAcyQ!1WpaMYGJJ8h2AJbR81y6VDBdXx5wmVhJgXgyG5mJ144ftQxO9EIoQTo8T0UzM1GQ0lnWjY0M99v7QCYxUAI_E3A$>. * *You no longer wish to receive these updates? Please reply to this email and we will delete you from our database.* _______________________________________________ open-regulatory-compliance mailing list open-regulatory-compliance@eclipse.org To unsubscribe from this list, visit https://accounts.eclipse.org