CRA 24h Clock · Sample Watch bulletin · September 2026

CRA24 Watch, 2026-09

Article 14 starts on 11 September 2026. The platform you must file through was still not publicly reachable when this bulletin was compiled.

Compiled 2026-09-03. Every claim below cites a primary source and the date it was read. Where something could not be verified it says [ei verifioitu] rather than being left out.

The clock

Reporting deadlines, all running from the moment you become aware:

What changed this month

ENISA updated three Single Reporting Platform guidance pages in August 2026

ENISA published dated guidance for Assigned Representatives: "CRA SRP - AR User registration" and "CRA SRP - AR Notification submission and update", both updated 3 August 2026, and "CRA SRP - AR Interface functions", updated 14 August 2026. These are the operational screens you will actually use, and they landed five weeks before the obligation applies.

Why it matters. If your reporting runbook was written before August, it predates the only official description of the submission interface. Re-read the runbook against the AR pages before 11 September.

Source: ENISA, Single Reporting Platform (SRP) (https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp), read 2026-09-02

There is no reporting API at launch

ENISA's SRP FAQ states: "Organisations might automate reporting workflows and integrate reporting requirements into their systems and databases, however no Application Programming Interfaces will be provided at this stage."

Why it matters. Everything up to submission can be automated, but the final filing is a human in a browser. That is a staffing question, not an engineering one: inside a 24 hour window you need a named person who can log in, plus a named backup.

Source: ENISA, SRP Frequently Asked Questions (https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/frequently-asked-questions), read 2026-09-02

Registration runs through EU Login and can be done before you have anything to report

ENISA's SRP FAQ states: "Assigned Representatives (ARs) of manufacturers or open-source stewards must have an EU Login account and use it to register on the SRP." A Primary AR registers by selecting the relevant CSIRT designated as coordinator.

Why it matters. An EU Login account is the one prerequisite that does not depend on the platform being live. Create it for the primary filer and at least one deputy now. The 24 hour clock does not pause for account creation.

Source: ENISA, SRP Frequently Asked Questions (https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/frequently-asked-questions), read 2026-09-02

A non-validated Assigned Representative may file up to 20 notifications

ENISA's SRP FAQ states: "Non-validated ARs will be able to submit up to 20 notifications for one manufacturer before validation becomes mandatory."

Why it matters. You are not blocked from filing while validation is pending, but the allowance is finite. Treat validation as a task with a deadline rather than something that happens on its own. Note that at least one widely shared secondary summary gave this number as 10; the figure above is read from ENISA's own FAQ.

Source: ENISA, SRP Frequently Asked Questions (https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/frequently-asked-questions), read 2026-09-02

The delegated act on CSIRT dissemination delays is in force

Commission Delegated Regulation (EU) 2026/881, adopted 11 December 2025, sets the conditions under which a CSIRT may delay disseminating a notification on cybersecurity grounds.

Why it matters. Your report can be held back from onward distribution without that being a fault in your filing. Do not treat silence after submission as evidence that the report failed.

Source: Euroopan komissio, CRA Reporting obligations (https://digital-strategy.ec.europa.eu/en/policies/cra-reporting), read 2026-09-02

Article 14 covers products already on the market

The Commission states: "As of 11 September 2026, manufacturers are required to report actively exploited vulnerabilities and severe incidents impacting the security of products with digital elements." The duty is framed by product status, not by placing date.

Why it matters. The common reading that only products shipped after September are in scope is wrong. Your evidence log has to cover the product lines you still support, including old ones.

Source: Euroopan komissio, CRA Reporting obligations (https://digital-strategy.ec.europa.eu/en/policies/cra-reporting), read 2026-09-02

Open, contested, or not yet published

The public URL of the Single Reporting Platform

Status: ei verifioitu.

What we checked: ENISA's SRP page states that "As of 11 September 2026 onwards, the SRP will be used by CSIRTs and manufacturers for mandatory reporting" and that the platform is under development. No public submission URL was present on that page when this bulletin was compiled.

What to do: Watch the ENISA SRP page. Do not build a runbook step around a URL that does not exist yet; build it around the EU Login account, which does.

Source: ENISA, Single Reporting Platform (SRP) (https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp), read 2026-09-02

Two ENISA pages disagree on when voluntary reporting opens

Status: ristiriita ensisijaisten lahteiden valilla.

What we checked: The ENISA SRP page says the platform "could be used by any natural/legal persons for voluntary reporting" as of 11 September 2026 onwards. The ENISA SRP FAQ says voluntary reporting "will be enabled in the next phase of the CRA SRP". Both pages were read on the same day.

What to do: Do not plan a low stakes practice filing through the voluntary channel on day one. Assume your first filing may have to be a real one, and rehearse against your own evidence log instead.

Source: ENISA, SRP Frequently Asked Questions (https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/frequently-asked-questions), read 2026-09-02

The published list of national CSIRTs designated as coordinators

Status: ei verifioitu.

What we checked: Registration requires selecting the CSIRT designated as coordinator for your Member State of main establishment. We did not locate a published, consolidated list of those designations from a primary source.

What to do: Determine your Member State of main establishment now and record the reasoning. That determination is yours to make and does not depend on the list being published.

Source: ENISA, SRP Frequently Asked Questions (https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/frequently-asked-questions), read 2026-09-02

What "becoming aware" means for an open source steward

Status: ohjeistus kesken.

What we checked: Section 9 of the Commission's implementing guidance, published 2026-07-27, addresses becoming aware, but frames it around a manufacturer and their product. The open question for stewards is being tracked publicly at orcwg/orcwg#261.

What to do: Whichever reading prevails, the two facts an authority asks for first are the same: a timestamped moment of awareness and a record of who made the actively exploited call. Both are what your evidence log records.

Source: Euroopan komissio, CRA implementing guidance (julkaistu 2026-07-27) (https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation), read 2026-09-02

Tool and template changes

Measured from the repository history for this month, not written by hand:

Your monthly evidence chain run

Your evidence log is only worth something if its chain is intact and you can show that it was intact before the incident, not after it.

CRA_CLOCK_LOG=<your path> node cra-clock.mjs verify

CRA_CLOCK_LOG=<your path> node cra-clock.mjs status

CRA_CLOCK_LOG=<your path> node cra-clock.mjs aware --product "<name>" --vuln <id> --source <url> --decided-by "<name>"

CRA_CLOCK_LOG=<your path> node cra-clock.mjs deadlines --aware <ISO timestamp>

Run the first command once a month and keep the output. It costs a minute and it is the difference between an evidence log and a text file.

Sources tracked

This bulletin is a regulatory tracking summary. It is not legal advice, and no response time or on-call service is promised or implied.