Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

ENISA updates its single-reporting platform FAQ

1 min read
12:09UTC

ENISA updated its FAQ for the Cyber Resilience Act Single Reporting Platform on 31 August, the mechanism through which a manufacturer reports an actively exploited vulnerability once instead of notifying every national authority.

TechnologyAssessed
Key takeaway

One EU reporting channel replaces twenty-seven, and the operational detail is arriving through an FAQ.

ENISA, the European Union Agency for Cybersecurity, updated its frequently asked questions for the Cyber Resilience Act Single Reporting Platform on 31 August 1. Under that platform a manufacturer or an open-source software steward reports an actively exploited vulnerability once, rather than notifying every national authority in every member state separately. The Cyber Resilience Act is the EU regulation setting cybersecurity requirements for products with digital elements, which in practice means almost anything sold with software inside it.

A single reporting channel changes what compliance costs a small vendor. Twenty-seven separate notification routes turn a duty into a legal project; one submission form turns it into a task. The FAQ is not law and it is not an obligation, though for a company deciding whether the duty applies to it, the operational answers arrive here rather than in the regulation's text.

ENISA operates as an agency rather than a regulator. It publishes, certifies, advises the Commission and supports member-state CERTs, and it cannot fine anyone. That distinction matters when reading its output as a signal, because nothing ENISA publishes carries a penalty behind it.

The agency had already mapped where the gaps sat when its NIS360 assessment put water, rail and wastewater in the EU risk zone . Its other August publication points at a similar problem from the other end: a Cyber Resilience Maturity Assessment Model for micro, small and medium-sized enterprises, released on 6 August, carrying no obligation at all 2. A voluntary self-assessment is aimed squarely at the firms least likely to sit down and complete one.

Deep Analysis

In plain English

The EU's Cyber Resilience Act requires companies that make hardware and software to report actively exploited security flaws. ENISA, the EU's cyber agency, updated its FAQ on 31 August for the Single Reporting Platform, the system that lets a company file one report instead of contacting every EU country separately. ENISA also published a maturity model on 6 August to help small and medium businesses assess their own cyber security readiness, since they are the least likely to do a formal self-assessment on their own.

Deep Analysis
Root Causes

The Single Reporting Platform exists because the Cyber Resilience Act would otherwise require a manufacturer or open-source steward to notify every national authority separately for one actively exploited vulnerability, which multiplies reporting burden without adding security value for each additional notification.

First Reported In

Update #13 · Four privileged platforms under live attack

European Union Agency for Cybersecurity· 5 Sept 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.