A manufacturer makes one Article 14 submission through the CRA Single Reporting Platform. It does not prepare one filing for the coordinating CSIRT and a second filing for ENISA.

The platform routes the notification to the coordinating CSIRT and makes it simultaneously accessible to ENISA, subject to the narrow information-access restrictions in Article 16(2). “One submission” describes this recipient routing; it does not collapse the 24-hour, 72-hour, and final stages into one event.

Design one submission record

Give each reporting stage a single internal identifier. Link the approved payload, attachments, submitter, submission timestamp, platform reference, and receipt to that identifier. Avoid parallel teams preparing nominally separate ENISA and CSIRT versions, which creates an unnecessary reconciliation problem.

If a national authority asks a follow-up question, record it as correspondence tied to the original platform case. Do not silently treat that contact as a replacement submission or edit the stored payload.

Use a separate stage identifier beneath the stable case anchor. The early warning, 72-hour notification, and final report are different filing events even though each uses the same entry route. Keep their approvals, payloads, completion evidence, and later corrections distinguishable.

Prevent duplicate work upstream

Give legal, product security, communications, and the reporter access to one controlled candidate packet. If a team needs a specialist working view, link it to the candidate and require approved changes to return through the same review. Do not maintain an “ENISA version” and a “CSIRT version” that can drift.

Before handoff, reconcile manufacturer name, product scope, awareness time, track, Member States, sensitivity, and measures. A second review copy is useful; a second external filing plan is not.

Distinguish delivery from acknowledgement

The submitter should confirm what the platform accepted and preserve the resulting evidence. A saved draft, a completed review, and a click on a button are not the same as a confirmed submission. Define the platform state or receipt that closes the internal filing task.

If the interface fails, retain the error, time, and attempted content, then use the current official support path. The response owner should continue tracking the legal deadline while the technical issue is escalated.

Define what happens when the team receives an acknowledgement for one attempt after preparing another. Compare identifiers and content before marking either complete. Preserve both attempts and have the accountable reporter decide which external event represents the filed stage.

Keep internal stakeholders aligned

Legal, product security, and communications may each need a working copy, but one controlled payload should be the source for the regulatory submission. Record every approved change before it enters the platform.

This model reduces duplicate work without inventing a false shortcut. There is one electronic submission per stage, one evidence trail, and multiple recipients reached through the platform’s legal routing.

Continue this workflow with the platform-route overview and the staged evidence trail.