How to submit to the ENISA Single Reporting Platform (there is no API)
Updated 2026-08-07
Submission is manual — and that is the honest starting point
ENISA has stated that there is no Single Reporting Platform (SRP) API at this stage. Article 14 notifications are submitted manually: a human logs in and enters the early warning, the 72-hour notification, and the 14-day final report into the platform. There is no supported way to file programmatically, and no vendor can change that. Treat any claim of "automated filing to ENISA" as a red flag.
Being clear about this up front is not a weakness — it is the reality your 24-hour process has to be built around.
What manual submission means for your process
Because a person is transcribing under time pressure, everything that can be prepared in advance should be:
- Pre-register an EU Login for the platform for the people who will submit. Doing this cold, inside the 24-hour window, is how deadlines get missed.
- Know your product registration details and keep them where the on-call person can reach them.
- Prepare the payload in the platform's field order. The fixed fields (manufacturer, contact, product) never change; only the incident specifics do. If your on-call engineer is drafting the report at 2am rather than transcribing a prepared one, the process is too slow.
The three submissions build on each other
The early warning (24h), the notification (72h), and the final report (14d) are not three separate efforts — each carries the prior content forward and adds detail. A prepared template that escalates through the three stages keeps them consistent and fast.
A readiness report can show you a filled-in mock early-warning payload for your own highest-risk finding, with the fields a human must complete highlighted — so the first time you see the shape of the submission is not during a real incident.
Questions
- Is there an API to file Article 14 reports automatically?
- No. ENISA has stated there is no Single Reporting Platform API at this stage. Submission is manual — a human enters the notification into the platform. Any tool claiming automated filing is claiming something that does not exist yet.
- What do I need before I can submit?
- A pre-registered EU Login for the platform, your product registration details, and a payload prepared in the platform's field order so you are transcribing, not drafting, inside the 24-hour window.
- Can I prepare the report in advance?
- You can prepare everything except the incident-specific facts. Pre-drafting the fixed fields and having a template in the platform's field order is the difference between a 20-minute submission and missing the deadline.
See your own 24-hour exposure
Paste a dependency manifest — free, no email, nothing stored.
Run the free readiness reportBank the awareness record
Reserve a founding place — £0 today, cancel any time before launch.
Reserve a founding place