ENISA's CRA Reporting Platform: What the 72-Hour and Final Reports Require
Updated 20 September 20263 min read
Every Article 14 report under the Cyber Resilience Act goes through ENISA's Single Reporting Platform. ENISA's CRA SRP Glossary (version 1.3, 10 September 2026) lists 39 fields: 18 common to both streams, 12 that apply only to an actively exploited vulnerability, and 9 only to a severe incident.
This page covers the stages after the early warning. For the 24-hour stage, see the early warning, field by field.
The 72-hour notification
Fields from the early warning carry forward and can be updated. What becomes newly required:
Actively exploited vulnerability
| Field | Limit |
|---|---|
| General information about the vulnerability and the exploit | 4,000 |
Severe incident
| Field | Limit |
|---|---|
| General information about the nature of the incident | 4,000 |
| Date and time you became aware | — |
| Date and time the incident occurred | — |
| Initial assessment of the incident | 4,000 |
Optional at this stage, but worth completing: corrective measures already taken (2,000), measures users can take (4,000), attack vector (255), CVE or EUVD identifier.
The sensitivity field
Field 15, considered sensitivity of information (255 characters), asks you to name the sensitive element and the consequence of premature disclosure. ENISA states expressly that a generic confidentiality statement is not acceptable.
Particularly Exceptional Circumstances
The PEC fields exist only at the 72-hour stage and only for a vulnerability. They are not available at the early warning or the final report, and there is no PEC option for a severe incident. A free-text field of 800 characters lets you explain the request to the coordinating CSIRT.
The final report
Actively exploited vulnerability — due 14 days after a fix is available
| Required field | Limit |
|---|---|
| Corrective or mitigating measures taken | 2,000 |
| Corrective or mitigating measures users can take | 4,000 |
| Date the corrective or mitigating measure became available | — |
| Details of the security update or corrective measure | 2,000 |
| Full description of the severity | 4,000 |
| Full description of the impact | 4,000 |
| Malicious actor — if the information is available | 100 |
The date the measure became available is what starts the 14-day clock. ENISA's FAQ confirms the platform shows no on-screen counter for this deadline: it cannot know when your fix shipped. Track it yourself.
Severe incident — due one month after the 72-hour notification
| Required field | Limit |
|---|---|
| Corrective or mitigating measures taken | 2,000 |
| Corrective or mitigating measures users can take | 4,000 |
| Applied and ongoing mitigation measures | 4,000 |
| Detailed description of the severity | 4,000 |
| Detailed description of the impact | 4,000 |
| Type of threat or root cause likely to have triggered it | 255 |
Three details that trip people up
- Severity and impact are two separate fields, each up to 4,000 characters, in both streams. Several published templates merge them.
- Root cause gets 255 characters. Mark it as preliminary if analysis is incomplete.
- The malicious actor gets 100 characters — roughly one line. Name the actor or point to an indicator reference; if attribution is unconfirmed, say so.
Sources
- ENISA, CRA SRP Glossary, version 1.3, 10 September 2026
- ENISA, Single Reporting Platform — FAQ, updated 17 September 2026
- Regulation (EU) 2024/2847, Article 14 and Article 16(2)
Position as at 20 September 2026. ENISA versions its Glossary: check the version number before relying on it. General information, not legal advice.