Stavenor

Guides

ENISA's CRA Reporting Platform: What the 72-Hour and Final Reports Require

Updated 20 September 20263 min read

Every Article 14 report under the Cyber Resilience Act goes through ENISA's Single Reporting Platform. ENISA's CRA SRP Glossary (version 1.3, 10 September 2026) lists 39 fields: 18 common to both streams, 12 that apply only to an actively exploited vulnerability, and 9 only to a severe incident.

This page covers the stages after the early warning. For the 24-hour stage, see the early warning, field by field.


The 72-hour notification

Fields from the early warning carry forward and can be updated. What becomes newly required:

Actively exploited vulnerability

Field Limit
General information about the vulnerability and the exploit 4,000

Severe incident

Field Limit
General information about the nature of the incident 4,000
Date and time you became aware
Date and time the incident occurred
Initial assessment of the incident 4,000

Optional at this stage, but worth completing: corrective measures already taken (2,000), measures users can take (4,000), attack vector (255), CVE or EUVD identifier.

The sensitivity field

Field 15, considered sensitivity of information (255 characters), asks you to name the sensitive element and the consequence of premature disclosure. ENISA states expressly that a generic confidentiality statement is not acceptable.

Particularly Exceptional Circumstances

The PEC fields exist only at the 72-hour stage and only for a vulnerability. They are not available at the early warning or the final report, and there is no PEC option for a severe incident. A free-text field of 800 characters lets you explain the request to the coordinating CSIRT.


The final report

Actively exploited vulnerability — due 14 days after a fix is available

Required field Limit
Corrective or mitigating measures taken 2,000
Corrective or mitigating measures users can take 4,000
Date the corrective or mitigating measure became available
Details of the security update or corrective measure 2,000
Full description of the severity 4,000
Full description of the impact 4,000
Malicious actor — if the information is available 100

The date the measure became available is what starts the 14-day clock. ENISA's FAQ confirms the platform shows no on-screen counter for this deadline: it cannot know when your fix shipped. Track it yourself.

Severe incident — due one month after the 72-hour notification

Required field Limit
Corrective or mitigating measures taken 2,000
Corrective or mitigating measures users can take 4,000
Applied and ongoing mitigation measures 4,000
Detailed description of the severity 4,000
Detailed description of the impact 4,000
Type of threat or root cause likely to have triggered it 255

Three details that trip people up

  1. Severity and impact are two separate fields, each up to 4,000 characters, in both streams. Several published templates merge them.
  2. Root cause gets 255 characters. Mark it as preliminary if analysis is incomplete.
  3. The malicious actor gets 100 characters — roughly one line. Name the actor or point to an indicator reference; if attribution is unconfirmed, say so.

Sources

Position as at 20 September 2026. ENISA versions its Glossary: check the version number before relying on it. General information, not legal advice.