
On 11 September 2026, the European Union’s Cyber Resilience Act began requiring manufacturers of products with digital elements to report actively exploited vulnerabilities and severe incidents within 24 hours of becoming aware of them. The duty runs through the EU Agency for Cybersecurity’s new Single Reporting Platform, which ENISA switched on the same day while describing it as having reached only “initial operating capability.” That the deadline and its supporting infrastructure arrived on the identical date is itself the story, and it comes with a genuine credit: a manufacturer selling into the EU can now file one exploited-vulnerability report and have it reach every relevant national authority, rather than notifying each member state separately.
This Pre-Mortem asks the questions a post-mortem would ask, before failure is possible: what is being bet on, what single assumption could break it, what got decided before the safeguards existed, who carries the pager when it fails, and what proof would settle whether it worked. It is the diligence a compressed rollout deserves before its first real test, not after.
The Bet
The EU is betting that centralising exploited-vulnerability and severe-incident reporting through one platform gives ENISA and national CSIRTs (Computer Security Incident Response Teams) EU-wide visibility into what is actually being attacked, and that manufacturers will treat a 24-hour clock as workable even while the tool underneath it is still being built out. The bet favours momentum over completeness. The European Commission’s own guidance on the CRA’s reporting obligations confirms the platform was already operational on 11 September 2026, the same day the 24-hour duty took effect, rather than waiting until it was finished. It also asks industry to build compliance discipline around a tool still being assembled, in the same quarter that discipline is tested.
The Assumption
The load-bearing belief is that a “single” platform stays meaningfully single even with core pieces missing. As the specialist tracker cyberresilienceact.eu reported on launch day itself, voluntary reporting under Article 15, a programming interface, and a field recording exactly when a manufacturer became aware of an incident all “did not arrive with it,” and access runs only through an Assigned Representative role via EU Login multi-factor authentication. If that gap persists, manufacturers with products across many jurisdictions and limited access routes could end up filing manually into individual CSIRTs anyway, the exact fragmentation Article 16 was written to end.
The Sequence
The Commission did not settle what counts as a manufacturer becoming “aware” of a reportable event, the trigger that starts every clock in the regime, until its guidance published on 27 July 2026, six weeks before the duty began. For most of the preceding compliance-planning year, manufacturers had no published definition of the one moment that decides whether a 24-hour window has even opened. ENISA’s own Assigned Representative registration guidance still carried dated updates in launch week itself, on 9 and 10 September 2026, the guidance for actually using the platform arriving alongside it rather than well ahead of it.
The Pager
ENISA’s Executive Director, Juhan Lepassaar, put his name to the launch, framing it as a step toward “a more resilient Digital Single Market,” and carries the operational pager for the platform itself. Above him sits European Commission Executive Vice-President for Tech Sovereignty, Security and Democracy Henna Virkkunen, who holds the political brief for EU cybersecurity policy, having worked on the Cyber Resilience Act dossier in Parliament. Beneath both, national market surveillance authorities enforce the penalty tier attached to Article 14 failures: up to €15 million, or 2.5 per cent of global turnover. No individual has been named as accountable for the missing programming interface and voluntary-reporting channel, only an agency-level pledge to keep improving.
The Proof
No public dashboard, uptime figure, or notification-volume metric has been attached to the platform’s launch, and ENISA’s own pledge to keep improving it carries no completion date. The measure that would actually settle the question, whether a report filed with one coordinating CSIRT reaches every other relevant CSIRT and ENISA at the speed the platform promises, has not been made public in any testable form. That will only become visible once a real, cross-border, multi-product incident runs through the system at volume, rather than from the demonstration traffic of launch week, and eighteen months allows roughly two CRA reporting cycles for that test to arrive.
Verdict
If ENISA closes the Single Reporting Platform’s programming-interface and voluntary-reporting gaps, and attaches a public date to doing so, before the platform faces its first genuinely cross-border, multi-CSIRT incident, then 11 September 2026 will read as a pragmatic phased launch that got the hardest deadline live on time. If those gaps are still open when that incident arrives, manufacturers already working to a 24-hour clock will discover that the single reporting platform was, in practice, still several platforms wearing one name.








