How to report to NCSC-NL under the CRA
The Cyber Resilience Act obliges the manufacturer to report an actively exploited vulnerability within 24 hours to the designated national CSIRT and to ENISA. If your main establishment is in the Netherlands, that CSIRT is NCSC-NL. This page explains who receives the notification, how it is filed and what to prepare before the emergency.
1. Who receives your notification: NCSC-NL
The Nationaal Cyber Security Centrum (NCSC-NL) brings the authority and the operational team together in one body. NCSC-NL operates from The Hague and has a tradition of open technical publishing that is stronger than the European average.
The chain is exactly this: the authority as the institution, NCSC-NL as the operational team that reads your notification and, together with ENISA, forms the recipient set out in Art. 14.
NCSC-NL is based in The Hague and operates under the Ministry of Justice and Security. Historically it served the administration and critical infrastructure, while businesses had separate counterparts — the Digital Trust Center and the CSIRT for digital service providers.
2. The national channel, in practice
The language of the notification can be Dutch or English: NCSC-NL routinely works in both and publishes much of its technical material in English.
The Netherlands has begun consolidating these organisations into a single national centre. That is a change in progress: check which desk is live at the moment you need it, rather than trusting a reference found in a two-year-old document.
3. The landscape around it
The NIS2 transposition accompanies that consolidation and widens the number of entities that must report. The Dutch model stays pragmatic and strongly oriented towards information sharing with the private sector.
For the CRA, the designation of the CSIRT receiving manufacturers' notifications follows the national implementation of the Regulation. During a reorganisation that check matters twice as much: do it before you file, not during.
One last practical point: the Netherlands has a long tradition of coordinated vulnerability disclosure, with national guidance predating the CRA and widely adopted. If your disclosure policy follows that model you are already close to what the Regulation asks for in Annex I.
4. How filing works, in short
Filing is not an email to the authority: it goes through the single reporting platform established by Art. 16, and access requires EU Login credentials validated beforehand.
The chain of deadlines — 24 hours, 72 hours, final report — is the same across the Union and is set out in full on the Art. 14 page. For the article’s other trigger the final deadline changes: it is on the severe incident page.
EU Login is not something you improvise. Register at least one person, confirm the account and enrol the second factor now, while there is no pressure — then keep the credentials retrievable by more than one hand. EU Login · Commission authentication
5. What to prepare before an incident
Five things, arranged calmly, make the difference between a report filed in time and one filed too late. The first is the contact point to NCSC-NL, designated and validated, with a named substitute: on the day of the case you do not go looking for whoever holds the credentials.
In the Netherlands it pays to record the date on which you verified the channel and the name of the contact: in an ecosystem being reorganised, a reference checked six months ago may no longer be the right one.
And a note on time: the Netherlands runs on CET/CEST. The twenty-four hours run at night and at weekends too. In an ecosystem that is reorganising, having the channel verified and the deputy named counts for more than personal acquaintance with a contact who may change role.
This guide describes our reading of the regulatory text and the public procedures; it does not constitute legal advice, and the platform's operational details may evolve.
Who receives your notification, country by country
Art. 14 sends the notification to two recipients: the CSIRT designated by your Member State, and ENISA. The CSIRT changes with the country. Pick yours and read who staffs it, how filing works and what to prepare in advance.
- ItalyCSIRT Italia
- GermanyCERT-Bund
- AustriaCERT.at
- FranceCERT-FR
- BelgiumCERT.be
- LuxembourgCIRCL
- SpainINCIBE-CERT
- NetherlandsNCSC-NL
- PolandCSIRT NASK
Nine countries. Designation for CRA purposes follows national implementation: check the one in force before you file.