Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What does the CSIRT designated as coordinator do after a CRA filing?
Updated
The CSIRT designated as coordinator (Article 3(51) of Regulation (EU) 2024/2847) receives Article 14 notifications via the single reporting platform and disseminates them. It may delay dissemination on cybersecurity-related grounds under Delegated Regulation (EU) 2026/881. This page is not legal advice and does not start a clock.
CRA CSIRT-coordinator interaction guide, last verified 8 September 2026 against Regulation (EU) 2024/2847 Articles 3(51), 14 and 16, Commission Delegated Regulation (EU) 2026/881 (OJ L, 20.4.2026; in force 10 May 2026), the European Commission's CRA reporting page (Commission materials, not the regulation), and ENISA Single Reporting Platform materials (agency guidance, not the regulation). It is not legal advice, not a filing, not a determination that the CRA applies, not a finding that a named CSIRT is YOUR coordinator, and not a substitute for counsel. This product does not talk to a CSIRT.
This is CSIRT interaction, not YOUR CSIRT
Audience: a CISO, incident responder, or compliance owner at an organisation that might be a manufacturer of products with digital elements under Regulation (EU) 2024/2847. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the CRA applies, that you are a manufacturer, that a product with digital elements has been made available on the Union market, that you have become aware, that a named CSIRT is YOUR coordinator, or that a delay ground is met.
Article 3(51) defines CSIRT designated as coordinator as a CSIRT designated as coordinator pursuant to Article 12(1) of Directive (EU) 2022/2555. That NIS2 designation is context for who the CRA recipient is. A NIS2 CSIRT class does not discharge CRA Article 14. This page does not name YOUR CSIRT and does not run the Article 14(7) cascade. Last verified 8 September 2026. Not legal advice.
- Statute versus guidance: Articles 3(51), 14 and 16 of Regulation (EU) 2024/2847, and Commission Delegated Regulation (EU) 2026/881, are legal requirements only if they apply. ENISA Single Reporting Platform materials are agency guidance, not the regulation. The Commission's CRA reporting page is Commission materials, not the regulation. This page quotes which kind of text it is relying on.
- The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page. The CRA-cluster Article 14 overview on this site is how Article 14 sits in the cluster. The statute-clock Article 14 guide on this site is the ladder under breach reporting. The where-to-submit guide on this site is the Article 14 channel page.
- The ENISA-workflow guide on this site is the platform-flow page.
- This product does not talk to a CSIRT, does not notify a CSIRT, and does not file with ENISA. A named human still submits.
Role and interaction after a filing — not a determination
After an Article 14 notification is submitted via the single reporting platform, several actors have distinct duties. The table is an aid. It is not a determination that YOU have filed, that a named CSIRT is YOUR coordinator, or that a clock has started. Last verified 8 September 2026. Not legal advice.
| Actor | What the cited text says happens after a filing | Kind of text | Last verified |
|---|---|---|---|
| Manufacturer | Article 14(1) and 14(3): notify simultaneously to the CSIRT designated as coordinator, in accordance with Article 14(7), and to ENISA, via the single reporting platform. Remaining stages (72-hour notification, final report), an intermediate report if requested under Article 14(6), and informing impacted users under Article 14(8) continue. A CSIRT delay of dissemination does not pause those manufacturer duties. | Legal requirement — Article 14. Only if the CRA applies. This page does not find that YOU are a manufacturer. | 8 September 2026 |
| CSIRT designated as coordinator — initially receiving | Article 16(2), first subparagraph: after receiving a notification, that CSIRT shall, without delay, disseminate the notification via the single reporting platform to the CSIRTs designated as coordinators on the territory of which the manufacturer has indicated that the product with digital elements has been made available. Article 16(2) also lets that CSIRT delay dissemination on justified cybersecurity-related grounds. Article 14(6) lets it request an intermediate report. Article 16(3) requires it to provide market surveillance authorities with the notified information necessary for their obligations. | Legal requirement — Articles 14(6), 16(2) and 16(3). This page does not name YOUR CSIRT. | 8 September 2026 |
| Other relevant CSIRTs | Recipients of dissemination under Article 16(2): the CSIRTs designated as coordinators on the territory of which the manufacturer has indicated that the product has been made available. Delegated Regulation (EU) 2026/881 Article 2 calls that recipient a 'relevant CSIRT'. They are not the filing desk. | Legal requirement — Article 16(2); Delegated Regulation (EU) 2026/881 Article 2. | 8 September 2026 |
| ENISA | Article 14(1) and 14(3): notified simultaneously via the single reporting platform, unless particularly exceptional circumstances apply as Article 16(2) states. Article 16(1): ENISA establishes and maintains the platform. Where a CSIRT delays dissemination, Article 16(2) requires that CSIRT to inform ENISA immediately of the decision, the justification, and when it intends to disseminate. | Legal requirement — Articles 14, 16(1) and 16(2). | 8 September 2026 |
| Market surveillance authorities | Article 16(3): after receiving a notification of an actively exploited vulnerability or a severe incident, the CSIRTs designated as coordinators shall provide the market surveillance authorities of their respective Member States with the notified information necessary for those authorities to fulfil their obligations under this Regulation. | Legal requirement — Article 16(3). This page does not treat a CSIRT filing as a market-surveillance determination. | 8 September 2026 |
| Impacted users | Article 14(8): after becoming aware, the manufacturer shall inform the impacted users of the product, and where appropriate all users, of that vulnerability or incident and, where necessary, of risk-mitigation and corrective measures. Where the manufacturer fails to inform users in a timely manner, the notified CSIRTs designated as coordinators may provide that information when considered proportionate and necessary. | Legal requirement — Article 14(8). Distinct from the CSIRT/ENISA filings. This page does not convert that duty into a 24-hour count. | 8 September 2026 |
Who the CSIRT designated as coordinator is — Article 3(51) and Article 14(7)
Article 3(51) is a definition, not a directory. Member States designate a CSIRT as coordinator under NIS2 Article 12(1). The CRA uses that designation as the Article 14 recipient. This page does not list national CSIRTs and does not find that a named team is YOUR coordinator. Last verified 8 September 2026. Not legal advice.
Article 14(7): notifications are submitted via the single reporting platform using the electronic notification end-point of the CSIRT designated as coordinator of the Member State where the manufacturers have their main establishment in the Union, and shall be simultaneously accessible to ENISA. Main establishment is where decisions related to the cybersecurity of the products are predominantly taken; if that cannot be determined, the establishment with the highest number of employees in the Union. If there is no main establishment in the Union, Article 14(7) sets a cascade: authorised representative, then importer, then distributor, then the Member State in which the highest number of users are located — based on information available to the manufacturer. This page does not run that cascade for YOU.
- ENISA's SRP FAQ (updated 8 September 2026) describes Assigned Representatives selecting the CSIRT designated as coordinator in the platform. That FAQ is agency guidance, not the regulation. The specific validation procedure and processing time, ENISA says, may vary between CSIRTs. That variance is operational practice, not Article 14.
- The where-to-submit guide on this site is the Article 14 channel page. The ENISA-workflow guide on this site is the platform-flow page. The statute-clock Article 14 guide on this site records what ENISA has published about the portal as of last verification.
Delayed dissemination — Article 16(2) and Delegated Regulation (EU) 2026/881
Dissemination is the default. Delay is the exception. Article 16(2), first subparagraph: after receiving a notification, the CSIRT designated as coordinator initially receiving the notification shall, without delay, disseminate the notification via the single reporting platform to the relevant CSIRTs. That is the legal requirement.
Article 16(2), second subparagraph: in exceptional circumstances and, in particular, upon request by the manufacturer and in light of the level of sensitivity of the notified information as indicated by the manufacturer under Article 14(2), point (a), the dissemination of the notification may be delayed based on justified cybersecurity-related grounds for a period of time that is strictly necessary, including where a vulnerability is subject to a coordinated vulnerability disclosure procedure as referred to in Article 12(1) of Directive (EU) 2022/2555. Where a CSIRT decides to withhold a notification, it shall immediately inform ENISA about the decision and provide both a justification for withholding the notification as well as an indication of when it will disseminate the notification. ENISA may support the CSIRT on applying those grounds.
A manufacturer request is not a delay. The CSIRT initially receiving the notification decides. This page does not find that YOUR notification meets a delay ground, and it does not start or pause a clock. Last verified 8 September 2026. Not legal advice.
- Delegated Regulation (EU) 2026/881 was adopted on 11 December 2025, published in the Official Journal on 20 April 2026 (OJ L, 2026/881), and entered into force on 10 May 2026 (Article 6: twentieth day following publication). ELI: http://data.europa.eu/eli/reg_del/2026/881/oj. It specifies terms and conditions for applying the Article 16(2) grounds. It is not Article 14, and it does not rewrite the 24-hour, 72-hour, or 14-day manufacturer marks.
- Confidentiality of the notified information is a delay theme in both Article 16(2) and the delegated act. TLP and PAP are named in Article 3 of the delegated act as examples of protocols that may mitigate handling risk so that delay is not needed. This page does not assign a TLP colour to YOUR notification.
- ENISA's SRP FAQ 21 (guidance) describes a platform field for particular exceptional circumstances in the 72-hour notification, and states that where that mark is used ENISA receives only partial information until the receiving CSIRT makes the full notification available. That field description is agency guidance on the platform, not a rewrite of Article 16(2).
| Ground | What the cited text says | Kind of text | Last verified |
|---|---|---|---|
| Default — disseminate without delay | Article 16(2), first subparagraph: the CSIRT initially receiving the notification shall, without delay, disseminate via the single reporting platform to the CSIRTs designated as coordinators on the territory of which the manufacturer has indicated that the product has been made available. | Legal requirement — Article 16(2). Only if a notification has been received. | 8 September 2026 |
| Exception — delay on justified cybersecurity-related grounds | Article 16(2), second subparagraph: exceptional circumstances; in particular upon manufacturer request and in light of the sensitivity indicated under Article 14(2)(a); period strictly necessary; including a coordinated vulnerability disclosure procedure under NIS2 Article 12(1). Immediate information to ENISA of the decision, the justification, and when dissemination will occur. | Legal requirement — Article 16(2). This page does not find that YOUR facts are exceptional. | 8 September 2026 |
| Delegated act — nature of the reported information | Delegated Regulation (EU) 2026/881 Article 3: the CSIRT initially receiving the notification may delay, for a period limited to that strictly necessary, dissemination of notifications or parts thereof to relevant CSIRTs where, in light of the sensitivity of the notified information, the cybersecurity risks posed by the dissemination outweigh its security benefits and those risks cannot be mitigated by placing restrictions on handling or further sharing through appropriate protocols, such as the Traffic Light Protocol (TLP) or the Permissible Actions Protocol (PAP), and where at least one of the listed conditions is met. Fetched limbs include: (a) the manufacturer has informed that CSIRT that an effective risk mitigation measure, such as a security update or user guidance, is expected to be made available within 72 hours — if it is not, that CSIRT shall disseminate; (b) the information in the notification is deemed sufficient, in light of the nature of the notified actively exploited vulnerability, to create an exploitation technique, particularly when the vulnerability can be easily identified and exploited by actors with limited skills and resources — once an effective risk mitigation measure is available, that CSIRT shall disseminate; and a later limb on coordinated vulnerability disclosure where that CSIRT is acting as a trusted intermediary in accordance with NIS2 Article 12(1), with dissemination when a delay is no longer strictly necessary and consent for disclosure by the parties involved in the CVD is given, in accordance with Article 16(6) of Regulation (EU) 2024/2847. The full Article 3 list is in the delegated act on EUR-Lex. This page does not invent a missing point. | Delegated act — legal requirement for applying Article 16(2) grounds. Last verified 8 September 2026 against the EUR-Lex text of Commission Delegated Regulation (EU) 2026/881 (OJ L, 20.4.2026). Not Article 14 itself. Not ENISA operational practice. | 8 September 2026 |
| Delegated act — a specific relevant CSIRT | Delegated Regulation (EU) 2026/881 Article 4: that CSIRT may delay dissemination of notifications or parts thereof to a specific relevant CSIRT where (a) the relevant CSIRT has been affected by a cybersecurity incident casting doubt on its ability to ensure the confidentiality of the notified information, or (b) it has sufficient reason to believe that the capabilities of the relevant CSIRT are inadequate to ensure that confidentiality. Under (a), delay may last until the relevant CSIRT has informed the CSIRTs Network that its ability to ensure confidentiality has been restored. Under (b), delay may last until that CSIRT has provided evidence that it has addressed the shortcomings identified. | Delegated act — legal requirement. This page does not find that a named CSIRT cannot keep a secret. | 8 September 2026 |
| Delegated act — the single reporting platform | Delegated Regulation (EU) 2026/881 Article 5: that CSIRT may delay dissemination of notifications via the single reporting platform where ENISA has informed the CSIRTs Network, in accordance with Article 16(4) of Regulation (EU) 2024/2847, that the single reporting platform has been affected by a cybersecurity incident casting doubt on its ability to ensure the confidentiality of notified information. | Delegated act — legal requirement. Distinct from ENISA FAQ 25 on a temporarily unavailable portal. | 8 September 2026 |
| What ENISA currently publishes about delay (guidance) | ENISA's SRP FAQ 21 (updated 8 September 2026) states that in particular exceptional circumstances the receiving CSIRT may delay or withhold dissemination, including at the request of the manufacturer, and points to the 11 December 2025 delegated act. FAQ 8 states that under exceptional circumstances dissemination may be delayed in accordance with Article 16(2). Those FAQs are agency guidance, not the regulation, and not a substitute for Article 16(2) or Delegated Regulation (EU) 2026/881. | Agency guidance, not the regulation. | 8 September 2026 |
Manufacturer continuing duties — a delay does not pause the ladder
Filing an early warning is not the end of Article 14. A CSIRT delay of dissemination is a CSIRT decision about sharing with other CSIRTs. It is not a stay of the manufacturer's remaining duties. This page does not start those clocks and does not pause them. Last verified 8 September 2026. Not legal advice.
| Duty | What the cited text says | Kind of text | Last verified |
|---|---|---|---|
| Remaining Article 14 stages | The 24-hour early warning, the 72-hour notification, and the final report (14 days after a corrective or mitigating measure is available on the actively-exploited track; one month after the 72-hour incident notification on the severe-incident track) are distinct marks. Completing one stage does not discharge the others. The statute-clock Article 14 guide on this site is the ladder. | Legal requirement — Article 14(2) and 14(4). This page does not start those clocks. | 8 September 2026 |
| Intermediate report on request | Article 14(6): where necessary, the CSIRT designated as coordinator initially receiving the notification may request manufacturers to provide an intermediate report on relevant status updates about the actively exploited vulnerability or severe incident. | Legal requirement — Article 14(6). Clock-start is a request, not becoming aware. | 8 September 2026 |
| Inform impacted users | Article 14(8) continues after the CSIRT/ENISA filing. If the manufacturer fails to inform users in a timely manner, the notified CSIRTs designated as coordinators may provide that information when considered proportionate and necessary. | Legal requirement — Article 14(8). Distinct from dissemination under Article 16(2). | 8 September 2026 |
| Sensitivity indication | Article 14(2)(b) and 14(4)(b): the 72-hour notification shall indicate, where applicable, how sensitive the manufacturer considers the notified information to be. Article 16(2) tells the receiving CSIRT to take that indication into account. Indicating sensitivity is not a delay, and it is not a finding that a delay ground is met. | Legal requirement — Articles 14(2)(b), 14(4)(b) and 16(2). | 8 September 2026 |
Legal requirement versus ENISA and Commission operational practice
The table below labels each text. Do not treat an ENISA FAQ as Article 16, and do not treat Article 16 as optional because a FAQ exists. Last verified 8 September 2026. Not legal advice.
| Text | What it is | What this page does not do |
|---|---|---|
| Regulation (EU) 2024/2847 Articles 3(51), 14 and 16 | Legal requirement — the regulation, only if it applies. | Does not apply those articles to YOU, and does not name YOUR CSIRT. |
| Commission Delegated Regulation (EU) 2026/881 | Delegated act specifying terms and conditions for applying the cybersecurity-related grounds in Article 16(2). Adopted 11 December 2025; OJ L, 20.4.2026; in force 10 May 2026. Not Article 14 itself. | Does not find that YOUR notification meets a delay ground. |
| Directive (EU) 2022/2555 Article 12(1) | NIS2 — the designation of a CSIRT as coordinator. Context for CRA Article 3(51). A different instrument. | Does not treat a NIS2 CSIRT class as discharging CRA Article 14. |
| European Commission CRA reporting page | Commission materials. Guidance, not the regulation. States that in exceptional circumstances the CSIRT may delay dissemination, and points to the 11 December 2025 delegated act. | Does not treat a Commission page as a substitute for Article 16(2). |
| ENISA Single Reporting Platform page, SRP FAQ (updated 8 September 2026), SRP factsheet | Agency guidance on the Article 16 platform. Describes CSIRT validation of Assigned Representatives, helpdesk support, and a particular-exceptional-circumstances field. Not the regulation. | Does not treat an ENISA FAQ as starting YOUR clock, naming YOUR CSIRT, or deciding a delay. |
What to do now
As of last verification on 8 September 2026, Article 14 applies from 11 September 2026 — three days from that verification date. The list below is operational preparation. It is not a determination that the CRA applies to YOU, that a named CSIRT is YOUR coordinator, or that a reporting clock has started. Walk it with counsel.
- Ask counsel whether YOU are a manufacturer of a product with digital elements made available on the Union market. This page does not run that test. Marking CRA in an obligation map is not that determination.
- If counsel says Article 14 may apply, identify the CSIRT designated as coordinator under Article 14(7). This page does not name YOUR CSIRT. The where-to-submit guide on this site is the Article 14 channel page.
- If counsel says a delay of dissemination may be in play, treat it as a CSIRT decision under Article 16(2) and Delegated Regulation (EU) 2026/881 — not a manufacturer self-help, and not a pause of the 24-hour / 72-hour / 14-day ladder. Open the statute-clock Article 14 guide on this site for those marks. This page does not start that clock.
- Do not treat an ENISA FAQ as Article 16. Do not treat a manufacturer sensitivity mark as a delay. Do not treat this product as talking to a CSIRT.
Checklist
This is a question list, not a filing, and not YOUR CSIRT determination. Walk it with counsel. The statute-clock Article 14 guide on this site is the ladder. The CRA-cluster Article 14 overview on this site is how Article 14 sits in the cluster.
- Which CSIRT designated as coordinator, if any, under Article 14(7)? This page does not run that cascade.
- Has an Article 14 notification been submitted via the single reporting platform? This page does not file.
- Dissemination without delay is the default (Article 16(2), first subparagraph). Delay is exceptional, on justified cybersecurity-related grounds, for a period strictly necessary.
- Manufacturer request and sensitivity indication are inputs to that CSIRT decision. They are not the decision.
- Delegated Regulation (EU) 2026/881 specifies the terms and conditions. This page quotes the limbs it fetched and does not invent a missing point.
- Remaining manufacturer stages, an Article 14(6) intermediate report if requested, and Article 14(8) user information continue. A delay of dissemination does not pause them.
- Document the assessment, including a no-delay and a no-notification decision. This page does not keep YOUR file.
Where this shows up in ShipReady Metrics
The signed-in app does not decide that the CRA applies, does not decide that you are a manufacturer, does not name YOUR CSIRT, does not decide that a delay ground is met, does not start an Article 14 clock, and does not talk to a CSIRT or ENISA. None of the surfaces below is 'CRA applies', 'this clock has started', 'this CSIRT is yours', or an instruction to submit a filing.
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organisation has classified as CRA-in-scope. That tracker does not start an Article 14 clock, does not decide that the CRA applies, and does not file with a CSIRT or ENISA. A named human still submits.
The obligation map lists frameworks the organisation has marked in-scope, including CRA if that mark is set. That mark is not a determination that the CRA applies, not a determination that you are a manufacturer, and not a finding that a named CSIRT is YOUR coordinator. The cyber risk register lives under Security. None of those surfaces notifies a CSIRT.
This page does not document a public demo URL. There is no public CRA demo path. ENISA's Single Reporting Platform is guidance on the Article 16 platform, not a submit button in this product.
Primary sources (last verified 8 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/2847 of 23 October 2024 (Cyber Resilience Act), Articles 3(51), 14 and 16, is a legal requirement only if it applies. Article 14 reporting applies from 11 September 2026 (Article 71(2)). Commission Delegated Regulation (EU) 2026/881 of 11 December 2025 specifies the terms and conditions for applying the cybersecurity-related grounds in Article 16(2) (OJ L, 20.4.2026; in force 10 May 2026; ELI: http://data.europa.eu/eli/reg_del/2026/881/oj). Last verified 8 September 2026 against the EUR-Lex text of that delegated act; this page quotes the limbs it fetched and does not invent a missing point. The European Commission's CRA reporting page is Commission materials, not the regulation. ENISA's Single Reporting Platform page, SRP FAQ (updated 8 September 2026) and SRP factsheet are agency guidance on the Article 16 platform, not the regulation. Directive (EU) 2022/2555 Article 12(1) is the NIS2 designation of a CSIRT as coordinator — context, a different instrument; the NIS2 incident-reporting guide is on this site. These are not a complete world list. Not legal advice.
The statute-clock Article 14 guide on this site is the live ladder under breach reporting. The CRA-cluster Article 14 overview on this site is how Article 14 sits in the cluster. The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page. The where-to-submit guide on this site is the Article 14 channel page. The ENISA-workflow guide on this site is the platform-flow page.
Frequently asked questions
Is this legal advice?
No. It is a CSIRT-interaction page distilled from Regulation (EU) 2024/2847 Articles 3(51), 14 and 16 and Commission Delegated Regulation (EU) 2026/881, with ENISA Single Reporting Platform materials and Commission CRA pages labelled as guidance, not the regulation. Whether the CRA applies, which CSIRT is yours, and whether a delay ground is met are legal questions for counsel on your facts. This page does not start a clock.
Does ShipReady notify a CSIRT?
No. The product does not talk to a CSIRT, does not notify a CSIRT, and does not file with ENISA. Signed-in Compliance → CRA reporting tracks recorded awareness for findings the organisation classified as CRA-in-scope. That tracker does not start an Article 14 clock and does not decide that a named CSIRT is YOUR coordinator. A named human still submits.
Can dissemination of an Article 14 notification be delayed?
Yes, as an exception. Article 16(2) of Regulation (EU) 2024/2847 lets the CSIRT designated as coordinator initially receiving the notification delay dissemination on justified cybersecurity-related grounds for a period that is strictly necessary, in particular upon manufacturer request and in light of the indicated sensitivity, including where a vulnerability is subject to coordinated vulnerability disclosure under NIS2 Article 12(1). Commission Delegated Regulation (EU) 2026/881 specifies the terms and conditions, including Article 3 (nature of the reported information; TLP or PAP as examples of handling protocols), Article 4 (a specific relevant CSIRT), and Article 5 (the single reporting platform). A manufacturer request is not a delay. The CSIRT decides. This page does not find that YOUR notification meets a delay ground. Last verified 8 September 2026. Not legal advice.
Does a CSIRT delay pause manufacturer Article 14 duties?
No. A delay under Article 16(2) is a CSIRT decision about sharing the notification with other CSIRTs. It does not pause the manufacturer's 24-hour, 72-hour, or 14-day marks, and it does not discharge Article 14(8) user-information duties or an Article 14(6) intermediate report if requested. This page does not start those clocks.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.