CRA operational readiness · 9 September 2026

CRA reporting starts on 11 September. The real test is whether the technical workflow works under a clock.

Article 14 of the Cyber Resilience Act applies from 11 September 2026. ENISA says the Single Reporting Platform is scheduled to become operational on the same date for mandatory manufacturer notifications. The immediate operational question is not whether the regulation has been read, but whether Product, Security, Engineering and Compliance can move from awareness to owned reporting data, submission access, remediation and evidence without avoidable delay.

What changes on 11 September 2026

Under CRA Article 14, manufacturers must report actively exploited vulnerabilities and severe incidents affecting products with digital elements through the Single Reporting Platform. The regulation provides for an early warning without undue delay and in any event within 24 hours of awareness, followed by a fuller notification within 72 hours where the relevant information has not already been provided.

ENISA's latest SRP FAQ, updated on 8 September 2026, states that the platform is scheduled to be operational from 11 September. ENISA's user-registration guidance also states that Assigned Representative users authenticate through EU Login and need MFA to access the platform.

Five things to test before the first real event

Authoritative awareness timeCan the organisation preserve the exact time it became aware of an actively exploited vulnerability or severe incident, and the source that established credibility?
24/72-hour ownershipIs there a primary owner, backup owner and escalation path for the early warning and follow-on notification workflow?
SRP access readinessDo the intended Assigned Representative users have working EU Login access with MFA, and is backup coverage understood before a real event?
Product and evidence retrievalCan product/version, impact, mitigation and supporting technical evidence be retrieved from named source systems quickly enough?
Remediation and closureDoes reporting connect to owned corrective action, technical verification and a reproducible evidence package rather than ending at notification?

The commercial implication is an execution gap, not another policy document

A policy, scanner, ticketing platform, SBOM and reporting portal do not automatically create a working response path. The expensive failure point is often between systems and teams: unclear ownership, slow evidence retrieval, fragile access, unresolved product mapping or remediation that cannot be verified afterwards.

That is why Enki Tech treats CRA as a technical readiness and operational assurance problem. The entry point is a bounded dry run; follow-on work should focus on the actual bottlenecks found in the exercise, including evidence retrieval, Microsoft Cloud and identity controls, workflow automation and verified remediation.

Primary sources