ENISA (European Union Agency for Cybersecurity)
The agency behind the CRA reporting platform and the EU vulnerability database
ENISA is the European Union Agency for Cybersecurity. Three parts of its work relate directly to SBOM and vulnerability management.
The CRA reporting platform
ENISA operates the Single Reporting Platform (SRP). Since 11 September 2026 manufacturers report actively exploited vulnerabilities and severe incidents there. Read more in Vulnerability reporting under the CRA.
The EU vulnerability database
The European Vulnerability Database (EUVD) was launched in May 2025 and was established under the NIS2 Directive. It gathers vulnerability information from CSIRTs, vendors and the CVE programme. Read more in What is a vulnerability?
Guidance on the supply chain
The report Good Practices for Supply Chain Cybersecurity from June 2023 describes practices for supply chain security and covers SBOM as a way to identify and handle vulnerabilities in software components. It is listed under References.
References
- Good Practices for Supply Chain CybersecurityPDF, enisa.europa.eu
Rapporten från juni 2023 lyfter vikten av transparens i leveranskedjan och rekommenderar SBOM för identifiering och hantering av sårbarheter i programvarukomponenter.
- ENISA: Single Reporting Platform (SRP)enisa.europa.eu
The platform where manufacturers report actively exploited vulnerabilities and severe incidents under the CRA.
- EUVD: European Vulnerability Databaseeuvd.enisa.europa.eu
The EU vulnerability database, operated by ENISA.