"If the reporting platform is unreachable, we cannot report. So nobody can blame us."
As of today, 11 September 2026, the reporting obligation under Article 14 of the Cyber Resilience Act (EU CRA) applies. The Single Reporting Platform (SRP) operated by ENISA, which all reports must go through, was meant to launch the same day. At the time of publishing this post, it was still down. The question is therefore not an exercise for the contingency plan but day-to-day business: what applies when the platform is offline or goes down? The answer is less comfortable than many manufacturers assume.

What is the Single Reporting Platform?
The Single Reporting Platform is the central reporting platform that ENISA operates under Article 16 of the Cyber Resilience Act. Manufacturers use it to report actively exploited vulnerabilities and severe incidents having an impact on the security of their product with digital elements. The report goes via the electronic reporting endpoint of the coordinator CSIRT in the member state of the main establishment and is simultaneously accessible to ENISA. For manufacturers with their main establishment in Germany, the coordinator CSIRT is CERT-Bund at the BSI.
You probably know the deadlines from my earlier posts on the September deadline and the 24-hour early warning: 24 hours for the early warning, 72 hours for the actual notification, 14 days or one month for the final report.
Why does a platform outage not stop the deadlines?
Article 14 of the Cyber Resilience Act ties the reporting obligation to a single trigger: your awareness of the actively exploited vulnerability or the severe incident. From that moment, the clock runs. The availability of the platform simply does not appear in the provision. There is no rule suspending the deadline, no exception for technical failures, no force majeure reservation.
ENISA confirms this reading in its FAQ on the Single Reporting Platform. During a temporary outage, manufacturers should wait and submit the report once the platform is available again. If a manufacturer considers immediate communication necessary, it can contact its responsible CSIRT directly. The decisive part is the follow-up sentence: even those who contacted the CSIRT directly must resubmit the report via the SRP as soon as it is available again.
For Germany, the BSI goes one step further and states explicitly that mandatory reports may exceptionally be submitted by email to CERT-Bund while the platform is temporarily unavailable. That is a pragmatic position, and in my view the right one. But it changes nothing about the principle: the outage shifts the reporting path, not the obligation.
In practice, this means for manufacturers:
- The 24-hour deadline for the early warning keeps running from awareness, even if the SRP does not respond.
- Anyone who sits out the outage without documenting and without using the fallback path carries the full risk of a missed deadline.
- Anyone who documents the failed attempt and reports by email in parallel can later prove they did everything that was possible.
Myth vs. Fact
Myth: If the Single Reporting Platform is down, the reporting obligation lapses and the deadlines pause until the platform is back up.
Fact: The deadlines under Article 14 of the Cyber Resilience Act run independently of the platform's availability. During an outage, manufacturers report directly to their coordinator CSIRT instead, in Germany by email to CERT-Bund at the BSI, and resubmit the report via the SRP once it is back up.
Concrete consequences for your reporting process
1. Put the fallback in writing in your reporting process now. For manufacturers with their main establishment in Germany, I recommend sending two emails simultaneously during an SRP outage: to CERT-Bund at the BSI (certbund@bsi.bund.de) and to the ENISA SRP helpdesk (cra-srp-helpdesk@enisa.europa.eu). For the content, follow the mandatory fields of the early warning, so that the later SRP report matches it. A process that is improvised only when it counts costs hours you do not have.
2. Document every failed attempt so it holds up as evidence. Timestamp, screenshot of the error message, sending time of the fallback emails. This documentation is your evidence to the market surveillance authority that the delay was the platform's fault, not yours. Without it, it is your word against a server log.
3. Resubmit the report via the SRP as soon as it is back online. This is the point that will most often be lost in practice: the email to CERT-Bund and ENISA does not replace the report via the platform. Only the resubmitted SRP report satisfies the obligation under Article 14(7). Define in your process who checks availability and who owns the resubmission.
What does this mean for your EU CRA roadmap?
Today marks the first of the two key dates: since 11 September 2026 the reporting obligations apply, and on 11 December 2027 the full application of the EU CRA follows. Handling a platform outage is a good example of why compliance with the Cyber Resilience Act is not a documentation project but a process topic: whoever has to report needs rehearsed procedures, and those procedures have to cover the exceptional cases. How the deadlines interlock is laid out in the CRA roadmap 2026/2027. What non-compliance costs is covered in the article on fines and penalties.
Frequently asked questions
Does the 24-hour deadline pause when the SRP is down? No. The deadline runs from the moment you become aware of the actively exploited vulnerability or the severe incident. The Cyber Resilience Act contains no provision that suspends the deadline during a platform outage.
Who do I report to in Germany when the platform is down? The BSI exceptionally accepts the report by email to CERT-Bund. I recommend writing to CERT-Bund (certbund@bsi.bund.de) and the ENISA SRP helpdesk (cra-srp-helpdesk@enisa.europa.eu) at the same time, and documenting both.
Does the email replace the report via the SRP? No. ENISA makes clear that the report must be resubmitted via the platform as soon as it is available again. The email preserves the deadline in the exceptional case, but it does not satisfy the form requirement of Article 14(7).
Does this also apply to manufacturers without a main establishment in Germany? The principle carries over, the addressee does not. What matters is the coordinator CSIRT of the member state where your main establishment sits; manufacturers without an establishment in the EU fall under the cascade in Article 14(9), which runs through the authorised representative, importer, distributor, or the member state where most users are located. Agree your fallback reporting path with that CSIRT before you need it.
What if the platform never launches or stays offline for days? Legally the same: Article 14 of the Cyber Resilience Act does not make the obligation conditional on the availability of the platform, so the fallback via the coordinator CSIRT remains the relevant channel for as long as the SRP stays down. Whether an authority could sanction a missed deadline when the legally prescribed reporting path itself was never available is an open grey area. Do not rely on it: anyone who has reported via the fallback and documented everything never has to have that argument in the first place.
Conclusion
An outage of the Single Reporting Platform is not a free pass but an exceptional scenario with a clear script: document the failed attempt, report by email to CERT-Bund and ENISA instead, resubmit via the platform. Anyone who writes this script only when the error message is on the screen loses the hours that matter. Our free CRA assessment shows you where you stand.
Every Friday I debunk a CRA myth here.