Article 14 of the EU Cyber Resilience Act applies from 11 September 2026. ENISA’s operational FAQ, updated on 4 September, now specifies how manufacturers and open-source software stewards must access the Single Reporting Platform. Each Assigned Representative must use a personal EU Login account with multi-factor authentication. A manufacturer may have one Primary Assigned Representative and up to 20 Secondary Assigned Representatives; the Primary Representative creates the manufacturer association and invites the others. The coordinating CSIRT validates that association, but pending validation does not prevent reporting and an unvalidated representative may submit up to 20 notifications. No API will be available at launch, so the initial 24-hour warning and later submissions must be entered through the platform interface. The platform will initially accept mandatory reports only. If it is unavailable, the manufacturer may contact the designated CSIRT where immediate communication is necessary, but must still submit through the platform once service is restored.
Why it matters
If your company sells software, connected equipment or another digital product under its own brand, appointing a reporting owner is no longer enough. The individual submitters need personal EU Login accounts with MFA, the Primary Representative must be able to invite deputies, and the first report cannot be automated through an API at launch.
The Underwriter’s take
- Confirm whether each branded connected product or software package makes the company a “manufacturer” under Article 3(13).
- Give the Primary Assigned Representative and at least one deputy personal EU Login accounts with MFA before 11 September.
- Prepare the 24-hour report for manual entry, including awareness time, manufacturer and product name, product version, summary and affected Member States.