ENISA's Single Reporting Platform — the EU's mandatory portal for vulnerability reports — went live September 1, 2026. Yesterday.
The enforcement date for using it is September 11, 2026. Nine days from now.
If your org ships any software, SaaS, or digital tool to EU customers, you need to know about this. Not next month. Now.
What just happened
The EU Cyber Resilience Act (CRA) has been law since 2024. Most small software teams heard about it and filed it away as a "2027 problem" because the full compliance deadline — CE marking, conformity assessments, software bills of materials — is December 11, 2027.
The catch: Article 14 reporting obligations are not 2027. They are September 11, 2026.
From that date, if you become aware of an actively exploited vulnerability in your product, you have 24 hours to file a report. Not to patch it. Not to issue a press release. To file a report with ENISA and your designated national CSIRT.
The portal to do that launched yesterday. Nine days before it becomes mandatory. Nobody got a head start.
Who this actually covers
"Products with digital elements" is the regulatory language. In plain terms: any software or hardware that connects to a network or device, sold commercially to EU customers.
That includes:
- SaaS tools with EU users
- Self-hosted software you charge for (support contracts, subscriptions, hosting)
- Open-source software you've built a commercial service around
The open-source exception is narrow. If you distribute for free with no commercial relationship attached, you're probably out of scope. The moment there's a subscription, a support contract, or paid hosting, you're in.
You don't have to be an EU company. Canadian startup with French customers? Covered. Ottawa-based AI vendor with a UK client list? Covered. Non-compliance runs up to €15 million or 2.5% of global revenue, whichever is higher.
What 24-hour reporting actually requires
When you discover an actively exploited vulnerability in your product, the CRA timeline looks like this:
- Hour 24: Initial report filed to ENISA and your national CSIRT
- Hour 72: Detailed notification with technical specifics
- Day 14: Final report with full assessment
"Actively exploited" is the trigger — not every CVE, not every bug. But if your monitoring picks up that attackers are actively using a flaw in your software, the clock starts immediately.
For a 10-person team, this means having a real process before September 11. Who sees the alert? Who decides whether it qualifies? Who actually files? If those answers require someone to read a policy doc they've never opened, you're not ready.
The SME guidance exists — most people haven't seen it
ENISA published an SME maturity self-assessment tool on July 13 specifically to help smaller organizations figure out where they stand. The European Commission followed on July 27 with a 67-example guidance document covering scope, reporting, and risk assessment — with flowcharts.
That material is genuinely useful. But it dropped six weeks before the enforcement date, which means a lot of small software vendors are going into September 11 having never opened it.
What you need before the 11th
This is not a 2027 compliance project. Right now, you need:
An in-scope inventory. Which of your products have EU users? Which are commercial? That's your compliance perimeter.
A one-page incident decision tree. When someone flags a potential exploit: who gets notified, who decides it qualifies, who files the report. Keep it simple enough that someone can use it at 11pm.
A point of contact established. If you're based outside the EU, you file through ENISA directly. If you have an EU establishment, you file through that country's CSIRT. Know which one applies before you need it.
A test login on the ENISA platform. Go create an account on the Single Reporting Platform before September 11, not during an incident.
The full CRA apparatus — conformity assessments, CE marking, SBOMs — comes in December 2027. You have time for that. But the reporting process needs to exist in nine days.
This is the moment to get ahead of it
Most of your competitors are not reading this. Most small software vendors have September 11 on nobody's radar. The firms that get this right early are the ones that won't have their first CRA experience be a live incident report under pressure.
This is the kind of operational setup we put in place with teams in a sprint — not a governance framework, not a consultant's binder. A working process that people actually use when something goes sideways. If you want to get this done before the deadline, we can help.