Skip to content
11 days until the Art. 14 reporting obligation (11 September 2026).
Documentation Support Risk class
05Blog & insight · Operations · 5 August 2026 · 7 min read

EU Login and the ENISA platform: prepare them before the emergency

Two administrative prerequisites run on timelines that are not yours: the EU Login credentials and the designation of the contact point to the national CSIRT. Requesting them on the day of the emergency means arriving late for a reason that has nothing technical about it.

Logging in on a laptop to an institutional portal
Photo: FlyD / Unsplash

What EU Login is, and why it comes first

EU Login is the European Commission's authentication system, the same account used to access dozens of EU institutional services. It is not a detail of the Cyber Resilience Act: it is the gateway. Under Art. 16 the reporting flow passes through the national access points of the ENISA Single Reporting Platform, and to reach those access points you need a working EU Login identity. No credential, no platform.

The problem is that this account does not appear the moment you need it. It has to be created in advance, tied to a real corporate address, and confirmed. It is exactly the kind of step that looks trivial until the day it is on the critical path of a 24-hour deadline.

Art. 16Notifications are submitted through a single reporting platform, accessed via the national CSIRT access points designated by the Member States.

Registration and confirmation take real calendar time

Creating an EU Login account is not instant in practice. You choose the address, you wait for the confirmation email, you set the password, you add a second factor, and — for a company — you often have to reconcile the account with an internal mailbox that is monitored rather than personal. Each of these steps can stall on something outside your control: an email in the spam folder, a colleague on leave, a phone number that changes.

None of this is difficult. All of it takes days, not minutes, once you count the human latency between the steps. Do it now, while nothing is on fire, and verify that you can actually log in — an account you created but never tested is not a prerequisite you have met.

The Single Reporting Platform: you file, with your own credentials

The ENISA Single Reporting Platform is the single entry point through which the notifications of Art. 14 are submitted. Filing is an act of the manufacturer, performed with its own EU Login credentials. No vendor, no consultant and no service provider files on your behalf: the identity that submits the early warning is yours, and it is your name attached to the timing.

The recipients are two: the designated CSIRT — for Italy, CSIRT Italia within ACN — and ENISA. This is why the account cannot be delegated away as an afterthought: whoever holds the credentials is the one who, at 23:40 on a Saturday, is able to submit. Decide in advance who that person is, and make sure a substitute holds working access too.

Two things follow. Identify in advance who will act as your designated representative (Assigned Representative) on the platform, and complete registration and association to the Single Reporting Platform following ENISA's guidance in force at the time — the procedure may change, so do not assume it is fixed. A tool can prepare the filing for you: CRAnotify assembles the content, the register and the dossier, and this preparation can run in parallel with the administrative validation — but it does not automate the final submission on the SRP. There is no automatic SRP API; the deposit stays an act of the manufacturer, with its own credentials.

The pre-flight checklist

Five things to settle before the first real report, each independent of the others and each requiring time that is not yours to compress:

  • Create the EU Login account on a monitored corporate mailbox, with a second factor and a designated substitute.
  • Verify access to the Single Reporting Platform — actually log in, do not assume it works.
  • Designate and validate the company contact point to CSIRT Italia (ACN).
  • Keep the product register, the support periods and the SBOM current, so you can tell in minutes which products are affected.
  • Publish a coordinated-disclosure channel (a security.txt) so reports reach a single, monitored address.

Points 1 to 3 depend on external parties and confirmation times; points 4 and 5 depend only on you. Start with the ones you do not control.

The failure mode: registering while the clock runs

The scenario is easy to picture. Reliable evidence arrives that a vulnerability in one of your products is being actively exploited. The 24-hour clock of Art. 14 starts at that instant — not when you finish setting up. And you are still creating the EU Login account, waiting for a confirmation email, discovering that the second factor is tied to a phone no one has, or that the only person who could designate the contact point is unreachable.

You will not miss the deadline for lack of technical skill. You will miss it because an administrative account, which takes days to set up cleanly, was left for the worst possible moment. Everything on the checklist is boring, cheap and slow — which is precisely why it has to be done before, not during.

For the full step-by-step on the contact point and CSIRT Italia see the dedicated how-to; for how the 24-hour, 72-hour and final-report deadlines are counted see the pillar on Art. 14.

This article describes our reading of the regulatory text and does not constitute legal advice.

Risk class