Cyber Resilience Act

Cyber Resilience Act · Article 14

Where to report under the CRA: the CSIRT coordinator in each member state

Since 11 September 2026 an actively exploited vulnerability or a severe incident is reported on ENISA's single reporting platform within 24 hours of becoming aware, with the notification at 72 hours, and the CSIRT designated as coordinator for the member state where the manufacturer has its main establishment receives it; pick the state and the route is written below.

A manufacturer with no main establishment in the EU reports to the coordinator of the state of its authorised representative; the article below has the whole rule.

The three clocks, from the moment of awareness

24 hours

Early warning to the platform.

72 hours

Notification with the details the platform asks for.

14 days

Final report on a vulnerability, counted from the day a corrective measure is available, not from awareness; for a severe incident, one month from the notification.

Work out your dates in the deadline calculator

The coordinator in every member state

ENISA published the list of CSIRTs designated as coordinators on 10 September 2026; read on 12 September 2026. In Croatia, Czechia the coordinator is a different body from the national CSIRT of the CSIRTs Network. ENISA's list

The CSIRT designated as coordinator in each member state, its contact page, and whether it differs from the national CSIRT
Member stateCoordinatorContact pageNational CSIRT
AustriaCERT.atComputer Emergency Response Team Austriacert.atcert.atThe same body
BelgiumCCBCentre for Cybersecurity Belgiumccb.belgium.beThe same body
BulgariaCERT BulgariaCERT Bulgariagovcert.bgThe same body
CroatiaNCSC-HRNational Cyber Security Centre of Croatiancsc.hrDifferent: CERT.hr
CyprusCSIRT-CYNational CSIRT-CYcsirt.cyThe same body
CzechiaNÚKIBNational Cyber and Information Security Agencynukib.gov.czDifferent: CSIRT.CZ
DenmarkFE DDISDanish Defence Intelligence Service, formerly CFCSfe-ddis.dkThe same body
EstoniaCERT-EECERT Estoniaria.eeThe same body
FinlandNCSC-FINational Cyber Security Centre Finlandkyberturvallisuuskeskus.fiThe same body
FranceCERT-FRCERT-FRcert.ssi.gouv.frThe same body
GermanyCERT-BundCERT-Bund at the BSIbsi.bund.debsi.bund.deThe same body
GreeceEL-CSIRTNational Cyber Security Authority CSIRTcyber.gov.grThe same body
HungaryNCSC HungaryNational Cyber Security Center of Hungaryncsc.gov.huThe same body
IrelandCSIRT-IENational Cyber Security Centre Irelandncsc.gov.ieThe same body
ItalyCSIRT ItaliaComputer Security Incident Response Team Italiaacn.gov.itThe same body
LatviaCERT.LVInformation Technologies Security Incident Response Institutioncert.lvThe same body
LithuaniaCERT-LTNational CERT of Lithuanianksc.ltThe same body
LuxembourgCIRCLComputer Incident Response Center Luxembourgcircl.luThe same body
MaltaMT-CSIRTMT-CSIRTmita.gov.mtThe same body
NetherlandsNCSC-NLNationaal Cyber Security Centrumncsc.nlThe same body
PolandCERT PolskaCERT Polskacert.plThe same body
PortugalCERT.PTCERT.PT at the CNCScncs.gov.ptThe same body
RomaniaDNSCRomanian National Cyber Security Directoratednsc.roThe same body
SlovakiaSK-CERTSK-CERTsk-cert.skThe same body
SloveniaSI-CERTSlovenian Computer Emergency Response Teamcert.siThe same body
SpainINCIBE-CERTINCIBE-CERTincibe.esincibe.esincibe.esincibe.esThe same body
SwedenCERT-SECERT-SEcert.seThe same body

In StandardOS the report is written before the clock runs out

StandardOS records the moment you became aware, runs the three clocks, and writes the early warning and the notification with the fields ENISA's platform asks for.

Which CSIRT do you report to under Article 14, and the rule that picks the stateWrite the incident response plan with the CRA clocks in itEvery member state, from the registers

This page in:DeutschFrançaisNederlandsEspañolDansk