Which CSIRT do I report to under the CRA?
Short answer. You report to the CSIRT designated as coordinator for the Member State where your main establishment in the Union is. But “main establishment” does not mean where your company is registered — it means where your cybersecurity decisions are predominantly taken.
If you have no establishment in the Union, a four-step cascade decides it: authorised representative, then importer, then distributor, then where most of your users are.
This is the question ENISA's Single Reporting Platform asks twice — once when you register, and again when you submit a report. It is the second thing it wants on both flows. And it is the one question in the whole reporting process that takes actual thought.
Why this matters more than it looks
On its own, picking a country from a dropdown sounds trivial. Two things make it not.
First, it gates the filing. You cannot submit a report without answering it, and you cannot answer it thoughtfully inside a 24-hour deadline while also handling an active exploit. Whoever is filing at 2am should be reading an answer, not deriving one.
Second, it is genuinely non-obvious — and not just for companies outside the EU. A manufacturer with engineering in one Member State and a registered office in another has two plausible answers and one correct one. See the next two sections.
The rule, if you are established in the EU
That CSIRT, on receiving your notification, shares it without undue delay with the other CSIRTs through the platform. So you file once, in one place, and the distribution is somebody else's job.
The trap: main establishment is not your registered office
Here is the part that catches people. The regulation defines main establishment as the Member State where the decisions related to the cybersecurity of its products with digital elements are predominantly taken.
That is a question about where the work happens, not where the paperwork lives. Consider a company incorporated in Ireland for tax and structuring reasons, whose entire firmware and security team sits in Poland, and whose security architecture, patching policy and disclosure decisions are all made there. Its main establishment for this purpose is Poland, and filing with the Irish coordinator would be wrong.
Distributed teams make this harder rather than easier, and the regulation has a fallback for exactly that: where the Member State cannot be determined, main establishment is taken to be the Member State where the manufacturer has the establishment with the highest number of employees.
Note the order. Headcount is the tie-breaker, not the primary test. You only reach it when cybersecurity decision-making is genuinely not concentrated anywhere.
If you have no EU establishment
Most of the manufacturers reading this are outside the Union — in the UK, the US, Taiwan, India, Australia — selling into the EU. The regulation runs a cascade. Take the first step that applies to you and stop:
| Order | The Member State where… |
|---|---|
| First | your authorised representative acting on your behalf for the highest number of products with digital elements is established |
| Then | the importer placing on the market the highest number of your products with digital elements is established |
| Then | the distributor making available on the market the highest number of your products with digital elements is established |
| Finally | the highest number of users of your products with digital elements are located |
Two things to notice about how this is written.
It is “highest number of products”, not highest revenue or largest partner. A small distributor who carries your whole catalogue can outrank a large one who carries two lines. That is a counting exercise, and it is one you can do today.
Each step only applies if the one above it does not. If you have an authorised representative, you stop there — the importer's location is irrelevant. If you have several authorised representatives, the one acting for the most products decides.
You decide this once, and it sticks
The regulation permits a manufacturer to submit notifications about any subsequent actively exploited vulnerability or severe incident to the same CSIRT designated as coordinator to which it first reported.
That is a small mercy with a real consequence: this is a one-time determination, not a per-incident calculation. Which is precisely why it is worth doing carefully, on a quiet afternoon, and storing the result somewhere findable rather than re-deriving it under pressure.
Why nobody can certify your answer — including us
The regulation qualifies the entire determination with five words: it is made based on the information available to the manufacturer.
That changes what a correct output looks like. Your CSIRT is not an objective fact a tool can compute and guarantee. It is a good-faith judgement on the facts you had. So any product — including ours — that prints “Your CSIRT is X” as a certified answer is over-claiming.
“On the information available to us on 13 September 2026, decisions related to the cybersecurity of our products are predominantly taken in [Member State]. Our main establishment for the purposes of Article 14 is therefore [Member State], and our coordinator CSIRT is [name].”
That shows your working, which is what a market surveillance authority would actually want to see, and it is the version that protects you if the determination is ever questioned. A bare country name does neither.
A worksheet you can fill in now
Five questions. The answers plus the rule above are your determination. Date it and store it with your technical documentation.
- Do you have an establishment in the European Union? Yes → answer 2 and 3. No → skip to 4.
- In which Member State are decisions about the cybersecurity of this product predominantly taken? Where the people who decide security architecture, patching and disclosure actually sit — not the registered office, unless they are the same place.
- If question 2 has no clear answer, which of your establishments has the most employees? Only needed when cybersecurity decision-making is genuinely distributed.
- No EU establishment — work down the cascade until one applies. Authorised representative with the most products, then importer with the most products, then distributor with the most products, then most users. Write down the name and Member State of whichever settles it.
- Your determination, and the date you made it. Then find your national CSIRT coordinator in the CSIRTs Network directory and record the name alongside it.
One deliberate omission: this page quotes the rules in Article 14(7) but never cites its sub-paragraph labels. Four published versions of that paragraph give three different internal numberings — two of them assigning the same labels to different content. A sub-label would look precise and be unreliable, so we describe the rule instead.
Work out which documents apply to your product
Eight questions, two minutes, no email needed. Your conformity route, every document that applies, and where each requirement comes from.
A subscription includes the reporting readiness pack on day one, with this worksheet and all six report drafts pre-filled for your product. €390 a year.