How to report to CERT.at under the CRA
The Cyber Resilience Act obliges the manufacturer to report an actively exploited vulnerability within 24 hours to the designated national CSIRT and to ENISA. If your main establishment is in Austria, that CSIRT is CERT.at. This page explains who receives the notification, how it is filed and what to prepare before the emergency.
1. Who receives your notification: CERT.at and GovCERT Austria
CERT.at is Austria's national CERT, hosted inside nic.at under a public mandate, while GovCERT Austria serves the administration: two teams, two audiences. CERT.at operates from Vienna, and its placement inside the domain registry is an Austrian choice, not the European norm.
The chain is exactly this: the authority as the institution, CERT.at as the operational team that reads your notification and, together with ENISA, forms the recipient set out in Art. 14.
CERT.at is Austria's national CERT and is not a ministry office: it operates inside nic.at, the national domain registry, under a public mandate. Alongside it sits GovCERT Austria, which serves the administration. For a private manufacturer the natural counterpart is CERT.at.
2. The national channel, in practice
The language of the notification is German; CERT.at also publishes advisories in English and routinely works in both. That second language is a practical convenience for a manufacturer whose technical documentation is in English.
The Austrian arrangement is therefore two-headed by design — a civil team and a government team — and competence is chosen by who you are, not by what kind of event you have. That is not an organisational detail: it changes which door you knock on.
3. The landscape around it
Austria built its cybersecurity framework around the national NIS implementing act and a coordination between the Federal Chancellery, the Interior Ministry and CERT.at. It is a distributed model with a light coordinating centre.
For the CRA this means that the designation of the CSIRT receiving manufacturers' notifications has to be checked against the national implementation in force, not inferred from the NIS structure. Check it before you file.
One last practical point: Austria leans heavily on European coordination and on the CSIRT networks rather than on national schemes of its own. For a manufacturer that translates into fewer local peculiarities and closer adherence to common European practice — good news if you operate in several Member States.
4. How filing works, in short
Filing is not an email to the authority: it goes through the single reporting platform established by Art. 16, and access requires EU Login credentials validated beforehand.
The chain of deadlines — 24 hours, 72 hours, final report — is the same across the Union and is set out in full on the Art. 14 page. For the article’s other trigger the final deadline changes: it is on the severe incident page.
EU Login is not something you improvise. Register at least one person, confirm the account and enrol the second factor now, while there is no pressure — then keep the credentials retrievable by more than one hand. EU Login · Commission authentication
5. What to prepare before an incident
Five things, arranged calmly, make the difference between a report filed in time and one filed too late. The first is the contact point to CERT.at, designated and validated, with a named substitute: on the day of the case you do not go looking for whoever holds the credentials.
In Austria it pays to settle in advance which of the two teams is yours and to get written confirmation of the channel: clearing that up while a twenty-four-hour deadline runs is the worst possible moment.
And a note on time: Austria runs on CET/CEST and shares much of the German holiday calendar. The twenty-four-hour deadline runs regardless. A rota that rests on a single named person, in a country with long bridge weekends, is a rota that will eventually miss a deadline.
This guide describes our reading of the regulatory text and the public procedures; it does not constitute legal advice, and the platform's operational details may evolve.
Who receives your notification, country by country
Art. 14 sends the notification to two recipients: the CSIRT designated by your Member State, and ENISA. The CSIRT changes with the country. Pick yours and read who staffs it, how filing works and what to prepare in advance.
- ItalyCSIRT Italia
- GermanyCERT-Bund
- AustriaCERT.at
- FranceCERT-FR
- BelgiumCERT.be
- LuxembourgCIRCL
- SpainINCIBE-CERT
- NetherlandsNCSC-NL
- PolandCSIRT NASK
Nine countries. Designation for CRA purposes follows national implementation: check the one in force before you file.