I wrote here about the CRA and the deployment plan: https://www.sorinmustaca.com/eu-cyber-resilience-act-cra-overview/
We are past September 11th and the Art. 14 of CRA is applying.
|
|
My company, Endpoint Cybersecurity, offers consulting on how to prepare for TISAX, ISO27001, NIS2, CSMS and SOC2 audits. It also works with companies to create and deploy a Secure Software Development Lifecycle, with various levels of AI support. |
|
||
| Get in touch with us here: https://www.endpoint-cybersecurity.com/contact/ |
Who is affected?
Is a a company from a non EU country, which sells software globally affected by the CRA Art. 14?
Any company is affected if the software is made available on the EU market. The CRA applies based on where the product is sold, not where the company is headquartered.
The CRA reaches beyond EU borders. As one legal summary puts it, The Cyber Resilience Act (Regulation (EU) 2024/2847) sets mandatory cybersecurity requirements for hardware and software products with a data connection sold in the EU.
It applies to manufacturers, importers, and distributors anywhere in the world.
Another source frames it directly: a US software vendor with EU customers and a Singaporean IoT company shipping to European retailers are both in scope.
The trigger is the product, not the seller’s nationality. One legal tracker states this plainly for a similar case: It binds the manufacturer wherever established, so a company in Türkiye that places a product on the EU market is directly liable in its own right.
For a company with HQ in a non EU country selling software globally:
In scope if: any part of that software is made available on the EU market, meaning EU-based customers can buy or use it, and the software qualifies as a “product with digital elements” under the CRA’s definition.
This Regulation applies to products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network.
Not in scope for that portion of business: sales confined to non-EU markets, if the company genuinely has no EU customers.
Practical obligation for a non-EU manufacturer
Since the company is established outside the EU, it likely needs an EU-based authorised representative, but not mandatory. Article 13 establishes the framework for authorised representatives, enabling manufacturers based outside the EU to appoint a natural or legal person established within the EU to act on their behalf for certain regulatory tasks. That representative keeps documentation available to regulators and cooperates with market surveillance authorities, but Manufacturers who appoint an authorised representative remain fully responsible for CRA compliance. The appointment does not transfer the manufacturer’s fundamental obligations.
On Article 14 specifically
If the software is in scope, the Article 14 reporting duties (24-hour early warning, 72-hour notification, 14-day final report) apply the same way they would to an EU-based manufacturer, filed through the ENISA Single Reporting Platform described below.
Cyber Resilience Act Single Reporting Platform
A company must register with the ENISA Cyber Resilience Act Single Reporting Platform (CRA-SRP). This is the single EU-wide portal for CRA reporting obligations, live at https://portal.cra-srp.enisa.europa.eu/.
Unless you are a CSIRT, you should register as a an Assigned Representative.
Create an account, if it is the first time you are visiting and install the app (everything will be faster next time).
It takes a few minutes and you need a mobile phone to do it properly.
Conclusions
ENISA was mandated to develop and operate the Single Reporting Platform as the common electronic reporting mechanism under Article 16 of the CRA. Notifications go through this one platform rather than to individual member state authorities separately.
Who this applies to
The obligations apply to manufacturers of products with digital elements as defined by the CRA who make their products available on the EU internal market. These obligations apply to all products already on the market, not just new ones.
Registration timing
There is no obligation to register before a report needs to be submitted. CRA-SRP registration and submission of reports can be completed within a few minutes if required. So a company does not need to pre-register speculatively. It registers when it actually needs to file a report.
Reporting deadlines once an event occurs
An early warning is due within 24 hours, a fuller notification with an initial assessment within 72 hours, and a final report within 14 days of a corrective or mitigating measure becoming available.
Who receives the report
The notification is addressed to the Computer Security Incident Response Team (CSIRT) where the manufacturer has its main establishment and, unless exceptional circumstances apply, the information is made available simultaneously to ENISA.
Dates
The CRA’s broader cybersecurity requirements (product design, conformity, and so on) apply later, from December 11, 2027.
One caveat: reporting through the SRP covers vulnerability and incident notification. It is separate from other CRA compliance steps, such as conformity assessment or CE marking, which are governed by different provisions. If your question is specifically about the reporting obligation, the SRP is the answer. If you need the full compliance picture (product requirements, documentation, market surveillance), that is a broader topic and worth clarifying separately.
Next: What do you need to be CRA compliant?
© Copyright 2026 Sorin Mustaca, All rights Reserved. Written For: Sorin Mustaca - Security & Technology
Want to work with me on this topic?
Check Endpoint Cybersecurity to see the consulting services we offer.


One thought on “Cyber Resilience Act Single Reporting Platform (CRA-SRP) obligations for software companies selling globally”
Comments are closed.