What this page does
- counts the early warning (24 hours) and the notification (72 hours) from the moment you became aware, in your local time and in UTC;
- counts the final report: 14 days after a corrective or mitigating measure is available for a vulnerability, one month after you submit the notification for an incident;
- lists the platform's fields with ENISA's numbers, the step that requires each one and its character limit, and copies a step's answers for pasting;
- shows which CSIRT you report to under Article 14(7), also when you have no establishment in the EU;
- drafts the notice to users that Article 14(8) asks for, from what you have already filled in.
The platform's own counter currently shows the 72-hour deadline as 48 hours after you submit the early warning, and it has no counter for the final report on a vulnerability (ENISA's questions and answers, 3 October 2026). ENISA says the counters are only aids and the legal deadline stays. This page counts from the moment you became aware, as Article 14 does.
What you report, and what you do not
You report an actively exploited vulnerability in your product: one for which there is reliable evidence that a malicious actor has exploited it in a system without the owner's permission (Article 3(42)). According to the Commission's questions and answers, a vulnerability found in testing or reported by a researcher in good faith, with no evidence of malicious exploitation, is not one. You also report a severe incident having an impact on the security of your product (Article 14(5)). One notification covers one vulnerability or incident, even if you have several branches in the EU.
Fines
Article 64(2) sets fines of up to EUR 15 million or, for an undertaking, up to 2.5% of its worldwide annual turnover, whichever is higher, for not complying with Article 14. Under Article 64(10)(a) those fines do not apply to microenterprises and small enterprises for missing the 24-hour deadline of the early warning; no other deadline is covered. Article 14 has applied since 11 September 2026. Article 64 is not among the provisions that apply early, so it applies from 11 December 2027 (Article 71(2)).
The rules themselves are on the CRA reporting page; whether the Act covers your product at all is on the Cyber Resilience Act page.
This page sends nothing to ENISA: you submit on the Single Reporting Platform yourself. Nothing you enter leaves your browser and nothing is stored, so download the register file to keep your work. ENISA's field list and guidance may change, and the Commission's guidance is not binding. This is not legal advice.
Sources
- Regulation (EU) 2024/2847 (Cyber Resilience Act), Articles 3, 14, 16, 64 and 71
- ENISA: CRA Single Reporting Platform glossary, version 1.4 (1 October 2026)
- ENISA: Single Reporting Platform, frequently asked questions (3 October 2026)
- ENISA: list of CSIRTs designated as coordinators (10 September 2026)
- European Commission: CRA reporting obligations