On 11 September 2026 manufacturers of products with digital elements will have to notify actively exploited vulnerabilities and severe incidents within twenty-four hours, as required by Article 14 of the Cyber Resilience Act. The channel through which they must comply, the single reporting platform run by ENISA, still has no public address, no dates for its testing period and no programming interfaces for automation. One further detail has emerged that says a great deal about how this infrastructure is coming into being: the ENISA page of frequently asked questions promised a preparatory webinar two weeks before the platform entered into service. That threshold fell on 28 August, no webinar was announced, and the sentence containing the promise has been deleted from the page. In the revision dated 31 August the FAQ appears expanded and rewritten, yet no trace of that webinar remains.
The preparatory webinar and the 28 August deadline
The promise sat in the answer to question 17 of the FAQ on the single reporting platform, the one devoted to training. In that version ENISA wrote that, to support preparation efforts, it “foresees to hold a webinar two weeks before the entry into service of the SRP”. According to the same FAQ, the platform is scheduled to be operational by 11 September 2026, the date on which the Article 14 obligation becomes applicable: two weeks before meant 28 August. It was the only commitment with a precise position in time within a framework otherwise made of open-ended formulas, and for that reason it carried particular weight: it allowed those who must organise themselves to fix a point on the calendar.
The removal of the sentence from the FAQ
28 August passed without any announcement. The answer to question 17 has been rewritten: the reference to the guidance and fact sheet published in July remains, as does the promise of further material at launch, now indicated as a user manual and tutorial videos, but every reference to the webinar has gone. The comparison can be verified: the copy of the page archived on 27 August still contained the sentence, while the later version does not. When the sentence disappeared, between 27 and 31 August, the page still declared 3 August 2026 as its last update: the removal happened without that date recording it. Only afterwards did ENISA publish a revision dated 31 August, which brings the questions to twenty-five and adds, among others, those on choosing the national CSIRT, on the platform’s languages and on its temporary unavailability, without however bringing the webinar back.
The missing public address and testing period
The removed webinar is the most eloquent detail, not the most consequential one. The FAQ still states that the platform will be accessible through a dedicated public URL to be communicated before it goes live, and the registration guidance still opens with the instruction to visit a URL to be provided at launch. The testing period meant to precede the entry into service remains announced without any date. Organisations hoping to integrate reporting into their own systems know, from the same FAQ, that no application programming interfaces will be provided at this stage. As for the format of the notifications, the template with the fields for the three phases, early warning within twenty-four hours, notification within seventy-two, final report, lives in an answer to the FAQ and not in an implementing act: Article 14(10) of the regulation gives the Commission the power, not the duty, to specify it, and that power has not been exercised to date.
An applicable obligation and a still provisional apparatus
The two planes should be kept apart. The reporting obligation does not depend on the completeness of the surrounding material: Article 14 applies from 11 September 2026 by virtue of Article 71 of the regulation, and the platform ENISA must establish under Article 16 is the instrument of compliance, as reconstructed on these pages when examining what starts on 11 September. Everything around that obligation, however, lives in guidance pages: who may notify and within what limits, how registration works, which fields to fill in, what preparation to expect. These are pages ENISA expands and updates continuously, which is natural for a tool under construction. The webinar episode shows that they can also contract: a commitment can be withdrawn with the same discretion with which it was made.
Critical profiles: reliance on pages that change
No rule prevents ENISA from amending an information page, which is not a legal act and binds no one. But the reliance operators place on those pages is no accident: the framework itself produces it, because no other operational source for the platform exists. Whoever is building an internal notification procedure is doing so, of necessity, on ENISA’s indications, including the quantitative ones, such as the ten-notification ceiling for a representative not yet verified, and the organisational ones, such as the suggestion to register only when a notification is actually needed. As has been seen, an indication can be withdrawn without, at the moment it happens, the update date recording it, even where the page is later expanded in plain sight: diligence then requires one further precaution, keeping a dated copy of the pages on which one’s choices rest. In a system which, across NIS 2, DORA and the Cyber Resilience Act, asks companies to document every assessment, it would be paradoxical for the informational basis of those assessments to remain the one thing undocumented.
What can be done in the time that remains
What the webinar was meant to teach will have to be learnt from the documents. The available actions remain those the published material allows: creating in advance the EU Login accounts of the people who will actually submit reports, identifying the coordinating CSIRT competent on the basis of the main establishment, mapping the fields of the notification template across the three phases so that the information needed in the first twenty-four hours is ready, and deciding who, within the internal chain, establishes the awareness of the vulnerability from which the clock starts running. To which one action should be added that rarely appears in preparation checklists: fixing in a dated copy the current state of ENISA’s guidance. Responsibility for choices of this kind, as the European framework has been repeating for months, runs up to the top of the company. If the platform opens on time on 11 September, the preparation done in these days will have served its purpose; if it does not, it will remain the proof that the organisation had done its part.




