ENISA published the contacts for the CSIRTs designated as coordinators under the Cyber Resilience Act on September 4, 2026, a table covering all 27 member states. Reporting obligations under Article 14 of Regulation (EU) 2024/2847 apply from September 11, 2026. Manufacturers have had the deadlines since the regulation was adopted; the list of who actually receives the report arrived with a week to spare.

The clocks run from awareness. An early warning goes to ENISA and the coordinating CSIRT within 24 hours of learning that a vulnerability in your product is being actively exploited or that a severe incident has occurred, a fuller notification follows at 72 hours, and a final report is due within 14 days of a corrective measure being available for a vulnerability, or one month for a severe incident. Article 14(7) decides where that report goes: the CSIRT in the member state of your main establishment, meaning the place where decisions about the cybersecurity of your products are predominantly taken. For plenty of manufacturers that is a development site rather than the registered office.

The Single Reporting Platform arrives thin. ENISA's own FAQ says no API will be provided at the initial release, so every notification gets typed into the interface by a person. Voluntary reporting under Article 15 is deferred to a later phase as well. Registration runs through an EU Login account with multi factor authentication enabled, and those accounts are personal, so the named filer and the backup each need one set up in advance.

Downtime does not buy time. ENISA guidance tells manufacturers to wait for the platform to come back and then submit, and allows direct contact with the CSIRT for urgent communication, while the platform submission stays mandatory. The 24 hour and 72 hour deadlines still run from the moment your organization became aware, so keep your own timestamped record of when that was rather than trusting what the platform displays back to you.

Device manufacturers should not read the MDR and IVDR carve out as a pass. Products regulated under those frameworks sit outside CRA scope, but companion apps, cloud services, accessories and general purpose software frequently do not, and each of those is a product with digital elements that owes Brussels a 24 hour early warning. Confirm your coordinating CSIRT and register the accounts this week. Opening the platform for the first time at hour 20 of a 24 hour clock is a bad plan.