ENISA, the European Union Agency for Cybersecurity, updated its frequently asked questions for the Cyber Resilience Act Single Reporting Platform on 31 August 1. Under that platform a manufacturer or an open-source software steward reports an actively exploited vulnerability once, rather than notifying every national authority in every member state separately. The Cyber Resilience Act is the EU regulation setting cybersecurity requirements for products with digital elements, which in practice means almost anything sold with software inside it.
A single reporting channel changes what compliance costs a small vendor. Twenty-seven separate notification routes turn a duty into a legal project; one submission form turns it into a task. The FAQ is not law and it is not an obligation, though for a company deciding whether the duty applies to it, the operational answers arrive here rather than in the regulation's text.
ENISA operates as an agency rather than a regulator. It publishes, certifies, advises the Commission and supports member-state CERTs, and it cannot fine anyone. That distinction matters when reading its output as a signal, because nothing ENISA publishes carries a penalty behind it.
The agency had already mapped where the gaps sat when its NIS360 assessment put water, rail and wastewater in the EU risk zone . Its other August publication points at a similar problem from the other end: a Cyber Resilience Maturity Assessment Model for micro, small and medium-sized enterprises, released on 6 August, carrying no obligation at all 2. A voluntary self-assessment is aimed squarely at the firms least likely to sit down and complete one.
