Prepare for CRA Article 14 reporting before the clock starts

Record when awareness began, classify the event, preserve the evidence and prepare reviewed reporting output for authorised human submission.

Prepare for the reporting obligations

CRA reporting obligations apply from 11 September 2026. ENISA identifies actively exploited vulnerabilities and severe incidents affecting product security as reportable categories. Record the evidence for the category decision; a scanner match alone does not establish the complete reporting assessment.

Rehearse awareness, ownership and review

Choose a supported release and run a clearly marked simulation. Identify the person who records awareness and its basis, the investigator, the reviewer and the authorised submitter. Check that the affected releases and supporting evidence can be found without relying on someone’s inbox.

Keep preparation separate from official submission

Conformesh preserves awareness evidence, report versions and reviewed handoff material. The initial ENISA Single Reporting Platform uses its web interface, without a submission API. An internal approval or export is not an official receipt: retain the actual confirmation and submitted material after a real handoff. Never submit synthetic exercise reports to the authority.

Check the current portal guidance

Prepare EU Login with multi-factor authentication and consult the ENISA FAQ for representative registration and validation. The FAQ updated 4 September recommends registering the organisation when a report is needed. Use the event-specific deadlines in the current guidance and rehearse backup coverage.

European Commission: Cyber Resilience Act · ENISA: Single Reporting Platform FAQ (checked 5 September 2026)

Explore the worked example · Check CRA readiness