On September 11th, 2026, the European Union Agency for Cybersecurity (ENISA) launched the Single Reporting Platform (SRP), fulfilling the first operational milestone of the Cyber Resilience Act (CRA).
The Single Reporting Platform serves as the central hub for incident reporting under the CRA, and specifically, it brings any products with digital elements in the EU market into mandatory alignment with the Act. That means vulnerabilities and security incidents must now be reported via the SRP according to a strict timeline. The process then disseminates the information to relevant Computer Security Incident Response teams (CSIRTs) in EU Member States where the affected product is also available. It’s a coordinated approach, helping ENISA and the response teams to move fast, mitigating cybersecurity risks and strengthening resilience across the EU.
Under the SRP, manufacturers must report actively exploited vulnerabilities within 24 hours. This detection phase is followed by a 14-day post-patch window.
This has a profound effect on exposing Harvest-Now-Decrypt-Later (HNDL) attacks – designed to capture today’s encrypted critical data with a view to exposing it when quantum technology tomorrow. With a fast, collaborative mechanism for observing systemic attacks, CSIRTs can cross-reference eavesdropping campaigns on today’s infrastructure. This visibility of the scale of threat posed by HNDL makes it much harder to justify delaying quantum migration.
The SRP also pushes organizations towards a formal cryptographic inventory – a key step for quantum-resilience. Organizations will need to determine whether their own infrastructure is affected by a cross-border CSIRT advisory issue, ensuring that vendors and third-parties have a legal obligation to fix legacy algorithms and aim for quantum-readiness. In addition, cryptographic agility becomes a priority, thanks to the CRA’s 14-day compliance window. The 14-day requirement for mitigation of a patch makes fixes impossible for legacy, non-agile codebases. In effect, crypto-agility has just become a mandatory requirement in the EU.
Ultimately, the SRP will act as a lens through which quantum risk is focused into an inescapable point. It is no longer possible to claim that the threat is a distant or hypothetical problem. Cryptographic weaknesses, side-channel attacks and vulnerabilities in public key infrastructure will increasingly become public regulatory knowledge.
Read more to find out about the Cyber Resilience Act
View the Press Release from ENISA on the launch of the Single Reporting Platform

