Share This Article
ENISA’s updated CRA Single Reporting Platform FAQs explain how manufacturers, including gambling operators and supplier, shall report actively exploited vulnerabilities and severe incidents from 11 September 2026, and what companies, including those operating in the gambling sector, need to put in place now to respond within the first 24 hours.
This is the third article in my analysis of the Cyber Resilience Act.
- In my first article, I looked at the European Commission’s guidance on the scope of the CRA, the products covered and the obligations that will apply. while
- in the second, I looked specifically at the implications of the CRA for gambling operators and suppliers, including the difficult questions around mobile applications, remote data processing solutions and third party platforms.
This article looks at a different part of the CRA: what happens when something actually goes wrong and a company has to report it also in the light of the newly updated ENUSA’s FAQs on the reporting platform.
The timing is important. The CRA reporting obligations will start applying on 11 September 2026 for both new and old products, while the CRA as a whole will become fully applicable on 11 December 2027. From 11 September, there will be situations where a company has only hours to understand what has happened, determine whether the CRA applies and take action and this is the aspect on which many of our clients are struggling.
What ENISA’s new FAQs clarify
ENISA’s Single Reporting Platform (SRP) is the mechanism through which manufacturers of products with digital elements will report, under the CRA, actively exploited vulnerabilities and severe incidents affecting the security of those products.
The updated FAQs provide practical information on the reporting process, registration, Assigned Representatives, the relevant coordinating CSIRT and the operation of the platform. ENISA has also published a detailed SRP Glossary setting out the information required at the different stages of a notification.
There are two mandatory categories of events:
- Actively exploited vulnerabilities, meaning vulnerabilities for which there is reliable evidence that a malicious actor has exploited them.
- Severe incidents, meaning incidents having a severe impact on the security of a product with digital elements.
The reporting process then develops in stages:
- an early warning has to be filed within 24 hours of becoming aware of the relevant event that ; while
- a more detailed notification follows within 72 hours.
For an actively exploited vulnerability, the final report is due within 14 days after a corrective measure has become available. For a severe incident, the final report is due within one month after the 72 hour notification.
The above does not mean that a company must have completed its investigation within 24 hours. It means that the company needs to be capable of making a legally and technically informed assessment with the information available at that point.
That requires preparation well before an incident occurs.
What kind of products fall within the CRA? The case of the gambling sector
The gambling sector is a good example of why CRA preparation cannot be limited to a general cybersecurity policy. The CRA analysis is product specific:
- A native sportsbook, casino or poker application distributed through an app store can fall within the definition of a product with digital elements.
- A browser based gambling platform is different since simply accessing a gambling service remotely through a browser does not, by itself, make the service a product with digital elements.
There are however components of the browser that might qualify as remote data processing solutions since the absence of that processing would prevent the product with digital elements from performing one of its functions. As such, even if some products are not in scope of the CRA, the regime might indirectly extend to them.
Likewise, in case of usage of a third party software, the operator might be requalified as manufacturer under the CRA, if it markets a product under its own name or trademark or substantially modifies it.
The assessment on the products that are within the CRA scope shall be performed before an incident. Once the 24 hour clock has started, it is not the right moment to discover who is legally responsible for the product.
What companies should do before 11 September
There are several practical steps that manufacturers and gambling companies should take now.
1. Identify the products that may trigger CRA reporting
Companies should identify which products with digital elements they manufacture or place on the EU market and determine which components and supporting services need to be considered.
The objective should be to reach a clear answer to four questions:
- What is the product?
- Who is the manufacturer?
- Which versions are currently supported?
- Which third parties are involved?
Without these answers, the reporting process is likely to become much more difficult when an incident occurs.
2. Identify the responsible entity
A gambling group may have one company operating the business, another company owning the intellectual property, another company developing the application and a technology provider operating the underlying platform. The company should determine which entity has the manufacturer role for each relevant product.
3. Make sure the right people can actually report
ENISA has provided specific guidance on the Assigned Representatives who will use the SRP. Companies should identify the relevant Primary and Secondary Assigned Representatives and ensure that they have the necessary access arrangements, including EU Login and MFA. They should also determine the relevant coordinating CSIRT.
4. Build the first 24 hour process
An incident response policy should establish who:
- receives the initial cybersecurity escalation
- determines whether the event may be reportable
- involves legal
- identifies the affected product and version
- collects the technical information
- records when the company became aware
- decides what can be reported within 24 hours
- submits the notification
- coordinates the 72 hour notification
- prepares the final report.
The company should also maintain a record of the decisions taken and the information available at each stage to submit it to regulators in case of enquiries. This aspect matters because a regulator may subsequently ask not only what happened, but also what the company knew at the relevant time and why it decided to act in a particular way. Every case shall be accompanied by a report that documents the decision taken by the company. That is where the defence dimension of CRA compliance becomes important.
The SRP does not replace the internal workflow
The CRA reporting platform is the reporting mechanism, while it does not determine whether the company has a reporting obligation or replace the internal process required to identify, investigate and classify an event. Companies shall organise their own internal workflows and databases, but the notification will be submitted through the platform interface.
This means that companies should consider creating an internal CRA workflow that records, at a minimum:
- when the company became aware of the event
- the affected product and version
- the preliminary classification
- the information available at 24 hours
- information that remains under investigation
- corrective and mitigating measures
- the person responsible for each action
- the 72 hour deadline
- the final reporting deadline
A properly designed workflow can help the company collect the relevant information, identify the deadlines and maintain a consistent record across cybersecurity, legal and business teams.
If you want to know more on the Cyber Resilience Act, you can read the following articles “Cyber Resilience Act guidance: which products, which obligations, from when” and “The Cyber Resilience Act for gambling operators and suppliers: what falls in scope and what has to be done“.

