Article 14 of the Cyber Resilience Act, Regulation (EU) 2024/2847, applies from 11 September 2026. From that day a manufacturer that becomes aware of an actively exploited vulnerability in a product it has placed on the EU market has 24 hours to file an early warning. The early warning goes to two places at once: ENISA, and the CSIRT designated as coordinator for the member state where the manufacturer has its main establishment. Both receive it through the single reporting platform ENISA runs under Article 16.
Every article written about the duty gets that far and then says "notify your national CSIRT". None of them says which one. Until 10 September 2026 none of them could, because no public list of the coordinators existed. On that day, the day before the platform opened, ENISA published one. This is it.
The table
These are the CSIRTs designated as coordinators under Article 12(1) of the NIS2 Directive, as ENISA published them on 10 September 2026, read on 12 September 2026. ENISA gives a country and one or more contact pages per state, and no team names; the names below are the ones the linked pages use for themselves. The link is the first page ENISA gives for the state.
| Member state | Coordinator | Full name | ENISA's contact page |
|---|---|---|---|
| Austria | CERT.at | Computer Emergency Response Team Austria | cert.at |
| Belgium | CCB | Centre for Cybersecurity Belgium | ccb.belgium.be |
| Bulgaria | CERT Bulgaria | CERT Bulgaria | govcert.bg |
| Croatia | NCSC-HR | National Cyber Security Centre of Croatia | ncsc.hr |
| Cyprus | CSIRT-CY | National CSIRT-CY | csirt.cy |
| Czech Republic | NÚKIB | National Cyber and Information Security Agency | nukib.gov.cz |
| Denmark | FE DDIS | Danish Defence Intelligence Service, formerly CFCS | fe-ddis.dk |
| Estonia | CERT-EE | CERT Estonia | ria.ee |
| Finland | NCSC-FI | National Cyber Security Centre Finland | kyberturvallisuuskeskus.fi |
| France | CERT-FR | CERT-FR | cert.ssi.gouv.fr |
| Germany | CERT-Bund | CERT-Bund at the BSI | bsi.bund.de |
| Greece | EL-CSIRT | National Cyber Security Authority CSIRT | cyber.gov.gr |
| Hungary | NCSC Hungary | National Cyber Security Center of Hungary | ncsc.gov.hu |
| Ireland | CSIRT-IE | National Cyber Security Centre Ireland | ncsc.gov.ie |
| Italy | CSIRT Italia | Computer Security Incident Response Team Italia | acn.gov.it |
| Latvia | CERT.LV | Information Technologies Security Incident Response Institution | cert.lv |
| Lithuania | CERT-LT | National CERT of Lithuania | nksc.lt |
| Luxembourg | CIRCL | Computer Incident Response Center Luxembourg | circl.lu |
| Malta | MT-CSIRT | MT-CSIRT | mita.gov.mt |
| Netherlands | NCSC-NL | Nationaal Cyber Security Centrum | ncsc.nl |
| Poland | CERT Polska | CERT Polska | cert.pl |
| Portugal | CERT.PT | CERT.PT at the CNCS | cncs.gov.pt |
| Romania | DNSC | Romanian National Cyber Security Directorate | dnsc.ro |
| Slovakia | SK-CERT | SK-CERT | sk-cert.sk |
| Slovenia | SI-CERT | Slovenian Computer Emergency Response Team | cert.si |
| Spain | INCIBE-CERT | INCIBE-CERT | incibe.es |
| Sweden | CERT-SE | CERT-SE | cert.se |
The same table, kept current and rendered in six languages, is on the reporting deadlines page, next to a calculator for the three deadlines.
Where the coordinator is not the national CSIRT
Two states designated a body other than the team the EU CSIRTs Network lists as their national CSIRT. In Czechia the coordinator is NÚKIB, the National Cyber and Information Security Agency, where the network lists CSIRT.CZ. In Croatia it is NCSC-HR, the national cyber security centre, where the network lists CERT.hr. A manufacturer in either state that wrote the national CSIRT into its incident procedure on the strength of the network's list, which is what this article suggested until the coordinators were published, has the wrong team in it. That matters more than it did a week ago: ENISA's own FAQ says a notification filed to the wrong coordinator may be invalidated and has to be filed again.
Two further states have two national teams in the network, and ENISA names one of each: CIRCL for Luxembourg, not GOVCERT.LU, and CERT Polska for Poland, not CSIRT-GOV. Everywhere else the coordinator is the national CSIRT.
The rule that picks the member state
Article 14(7) decides which state's coordinator gets the notification, and it is a rule about the company, not about where the vulnerability was exploited or where the affected users sit.
- The member state in which the manufacturer has its main establishment in the Union, which the Regulation defines as the state "where the decisions related to the cybersecurity of its products with digital elements are predominantly taken". If that cannot be determined, the state with the manufacturer's largest number of employees in the Union.
- If the manufacturer has no main establishment in the Union, the member state of its authorised representative.
- Failing that, the member state where the importer is established, and then the distributor.
- Failing all of those, the member state where the manufacturer is aware of the largest number of users.
So a manufacturer in Austria with customers everywhere in the EU reports to CERT.at, once, for the whole EU. A manufacturer outside the EU with an authorised representative in Ireland reports to Ireland's coordinator. You file once. ENISA's FAQ adds the corollary the Regulation only implies: one notification per vulnerability or incident for the whole corporate group, however many EU subsidiaries it has, and coordinating internally so that it is filed once is the manufacturer's job. Sharing the notification onward with other member states' coordinators and the market surveillance authorities is the job of the platform and the receiving CSIRT under Articles 14 and 16, not yours.
What to do with it before hour zero
Three things, in this order, and each takes minutes.
Write down your member state and your coordinator. Apply the Article 14(7) rule above to your company, find the row, and put the answer in the same document that names who files the report. At hour twenty-three of an incident, nobody should be reading this article for the first time, and nobody should be choosing between two drop-down entries.
Create the EU Login accounts now; register on the platform when you need it. The platform runs on EU Login and requires multi-factor authentication on the personal account of whoever reports. That account can and should be created before you ever need it, for the person who reports and for their deputy, because the 24-hour clock does not pause for annual leave. Registration on the platform itself is a different matter: ENISA advises manufacturers to register, and to start the coordinator's validation of their representative, only when they have a specific notification to submit, and says the registration takes a few minutes once the EU Login exists. How the platform works, step by step, is a separate article.
Decide what "became aware" means for you. The 24-hour and 72-hour clocks both run from the moment of awareness, and the Commission's guidance of 27 July 2026 sets the bar at a reasonable degree of certainty that a vulnerability in your product is being actively exploited: not the first rumour, not completed forensics. A team that has not decided whether a scanner alert, a customer email or a confirmed exploit is the trigger will argue about it while the hours run.
The 24 and 72 hours are the deadlines everyone quotes. The final report has a different anchor, and most write-ups get it wrong.
Sources
- Regulation (EU) 2024/2847, Article 14(1), (2), (7) and Article 16, and Article 71(2) for the application date.
- Directive (EU) 2022/2555 (NIS2), Article 12(1), the coordinator designation.
- ENISA, "List of CSIRTs Designated as Coordinators", last updated 10 September 2026, read 12 September 2026.
- The CSIRTs Network member list, csirtsnetwork.eu, read on 4 September 2026, for the national CSIRTs the coordinators are compared with.
- ENISA, single reporting platform FAQ and guidance pages, updated 9 to 11 September 2026.
- European Commission guidance C(2026) 5252 of 27 July 2026 on the reporting obligations.
This is not legal advice. Article 14 is a page and a half, and the article references above are there so you can read it yourself.