[
Date Prev][
Date Next][
Thread Prev][
Thread Next][
Date Index][
Thread Index]
[
List Home]
|
Re: [open-regulatory-compliance] SRP - Again updated
|
No problem, it looks like ENISA is pushing updates to the website in pieces.
Again, a NEW question was at 9 utc added, also some changes this morning at 4 utc...
New
-
Q30 "I am not a manufacturer. How can I report a vulnerability or security issue?"
(tagged [NEW]): non-manufacturers are told to contact their national CSIRT directly, since the platform currently supports only mandatory manufacturer notifications under Art. 14; ENISA warns such a submission "might be marked as 'invalid' in the SRP"
(the page's own sentence, missing its closing full stop, reproduced verbatim). Count 29 → 30.
Viele Grüße,
Steffen Zimmermann
Industrial Security @ VDMA
Von: Juan Rico <juan.rico@xxxxxxxxxxxxxxxxxxxxxx>
Datum: Dienstag, 8. September 2026 um 07:33
An: Open Regulatory Compliance Working Group <open-regulatory-compliance@xxxxxxxxxxx>
Cc: Steffen Zimmermann <steffen.zimmermann@xxxxxxx>
Betreff: Re: [open-regulatory-compliance] SRP - Again updated
Thanks a lot for the update and the links Steffen!
Dear all,
the FAQ or ENISA was updated some hours ago - again - and now presents new entries:
Two new questions
Q28 [NEW] "How do I connect to the CRA Single Reporting Platform?" — the URL, the "Assigned Representative" choice on the landing screen, and "The portal will be available from 11 September 2026.“
Q29 [NEW] "When do the reporting obligations start?" — Art. 14 for manufacturers from 11 September 2026; Art. 24(3) for open-source software stewards from 11 December 2027 per Art. 71(2); mandatory notifications go through the SRP, with a pointer to
FAQ 25 for outages.
and, finally, the website has been officially disclosed:
It is hard to keep track of the changes, so I use AI routines to fill this changelog here:
Mit den besten Grüßen,
Steffen Zimmermann