# ENISA (European Union Agency for Cybersecurity)

The agency behind the CRA reporting platform and the EU vulnerability database

> ENISA operates the Single Reporting Platform for the CRA and the European Vulnerability Database (EUVD), and publishes guidance on supply chain security.

Updated: 5 October 2026  
URL: https://sbom.se/en/resources/enisa

ENISA is the European Union Agency for Cybersecurity. Three parts of its work relate directly to SBOM and vulnerability management.

## The CRA reporting platform

ENISA operates the Single Reporting Platform (SRP). Since 11 September 2026 manufacturers report actively exploited vulnerabilities and severe incidents there. Read more in [Vulnerability reporting under the CRA](https://sbom.se/en/cra/vulnerability-reporting).

## The EU vulnerability database

The European Vulnerability Database (EUVD) was launched in May 2025 and was established under the NIS2 Directive. It gathers vulnerability information from CSIRTs, vendors and the CVE programme. Read more in [What is a vulnerability?](https://sbom.se/en/vulnerabilities/what-is-a-vulnerability)

## Guidance on the supply chain

The report Good Practices for Supply Chain Cybersecurity from June 2023 describes practices for supply chain security and covers SBOM as a way to identify and handle vulnerabilities in software components. It is listed under References.

## References

- [Good Practices for Supply Chain Cybersecurity](https://www.enisa.europa.eu/sites/default/files/publications/Good%20Practices%20for%20Supply%20Chain%20Cybersecurity.pdf): Rapporten från juni 2023 lyfter vikten av transparens i leveranskedjan och rekommenderar SBOM för identifiering och hantering av sårbarheter i programvarukomponenter.
- [ENISA: Single Reporting Platform (SRP)](https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp): The platform where manufacturers report actively exploited vulnerabilities and severe incidents under the CRA.
- [EUVD: European Vulnerability Database](https://euvd.enisa.europa.eu/): The EU vulnerability database, operated by ENISA.
