How to report to CERT-Bund under the CRA
The Cyber Resilience Act obliges the manufacturer to report an actively exploited vulnerability within 24 hours to the designated national CSIRT and to ENISA. If your main establishment is in Germany, that CSIRT is CERT-Bund. This page explains who receives the notification, how it is filed and what to prepare before the emergency.
1. Who receives your notification: BSI and CERT-Bund
The Bundesamt für Sicherheit in der Informationstechnik (BSI) is the federal information security authority, and CERT-Bund is the team operating inside it. BSI is based in Bonn, employs well over a thousand people and is also a certification body.
The chain is exactly this: the authority as the institution, CERT-Bund as the operational team that reads your notification and, together with ENISA, forms the recipient set out in Art. 14.
BSI is a federal authority based in Bonn with the largest technical apparatus among European cybersecurity agencies. CERT-Bund is its operational team: it takes in reports, correlates them and issues warnings. For a manufacturer, BSI is the institution and CERT-Bund is who actually reads the text you send.
2. The national channel, in practice
The language of the notification is German. BSI publishes advisories and bulletins in German and runs separate channels for operators in regulated sectors and for manufacturers: which one applies for CRA purposes follows the national implementation.
If you already report as a NIS entity you know that route. The CRA does not replace it and is not absorbed into it: two separate duties, with different triggers, that can arise together from the same event.
3. The landscape around it
Germany confirmed BSI as the central national authority in its NIS2 implementing act. The result is an ecosystem where CERT-Bund is the operational desk for most cyber reporting duties.
For the CRA that is not an automatic answer: designating the CSIRT that receives manufacturers' notifications follows the national implementation of the Regulation. Check the designation in force before you file; do not derive it from NIS2.
One last practical point: BSI is also a certification body and maintains long-standing national schemes alongside its part in the European framework. If your product falls among the critical ones and needs certification, the counterpart is the same body that receives your reports. In Germany that concentration is sharper than elsewhere and is worth factoring into planning.
4. How filing works, in short
Filing is not an email to the authority: it goes through the single reporting platform established by Art. 16, and access requires EU Login credentials validated beforehand.
The chain of deadlines — 24 hours, 72 hours, final report — is the same across the Union and is set out in full on the Art. 14 page. For the article’s other trigger the final deadline changes: it is on the severe incident page.
EU Login is not something you improvise. Register at least one person, confirm the account and enrol the second factor now, while there is no pressure — then keep the credentials retrievable by more than one hand. EU Login · Commission authentication
5. What to prepare before an incident
Five things, arranged calmly, make the difference between a report filed in time and one filed too late. The first is the contact point to CERT-Bund, designated and validated, with a named substitute: on the day of the case you do not go looking for whoever holds the credentials.
In Germany it pays to establish early whether your company is already registered with BSI for other duties: contact point and credentials may partly overlap, and settling that calmly beats discovering it on the day of the case.
And a note on time: Germany runs on CET/CEST and the Länder keep different public holidays. Art. 14's twenty-four hours know no holidays, regional or national. If your rota follows a local calendar, check that it also covers the days when the office is shut in one region only.
This guide describes our reading of the regulatory text and the public procedures; it does not constitute legal advice, and the platform's operational details may evolve.
Who receives your notification, country by country
Art. 14 sends the notification to two recipients: the CSIRT designated by your Member State, and ENISA. The CSIRT changes with the country. Pick yours and read who staffs it, how filing works and what to prepare in advance.
- ItalyCSIRT Italia
- GermanyCERT-Bund
- AustriaCERT.at
- FranceCERT-FR
- BelgiumCERT.be
- LuxembourgCIRCL
- SpainINCIBE-CERT
- NetherlandsNCSC-NL
- PolandCSIRT NASK
Nine countries. Designation for CRA purposes follows national implementation: check the one in force before you file.