The EU CRA now has a deadline, not
just a name.

From September 11, 2026, manufacturers selling into the EU must report actively exploited vulnerabilities within 24 hours, or face fines up to €15 million. Here's what the EU Cyber Resilience Act requires, and how CyBeats gets you ready before the clock starts.
CRA Reporting Clock
Article 14 comes into force
11.09.2026
Applies to products already on the EU market, not just new releases.
Early warning
24 hours
Full notification
72 hours
Final report
14 days

The rules changed. Compliance is no longer optional.

The EU's first horizontal cybersecurity law for products with digital elements: a legal mandate for a governed SBOM System od Record on every product, and a strict clock for reporting actively exploited vulnerabilities once they're found.

It reaches manufacturers, importers, and distributors regardless of where they're based. If your product connects to a network and reaches an EU customer, you're in scope.
At a Glance
Regulation
(EU) 2024/2847
Entered into force
Dec 10, 2024
SBOM format
CycloneDX/SPDX
Reporting platform
ENISA SRP
Regulation
15M/2.5% turnover

Three dates.
One of them is closer than you think.

DEC 10, 2024

Entered into force
The CRA becomes EU law. The phased compliance clock starts.

SEP 11, 2026

Reporting obligations live
Article 14: actively exploited vulnerabilities and severe incidents must be reported to ENISA and your national CSIRT, on a 24-hour clock.
Reporting obligations live

DEC 11, 2027

Full CRA application
Essential cybersecurity requirements, SBOM obligations, conformity assessment, and CE marking all apply.

This reaches further than most teams expect.

Reporting a vulnerability within 24 hours means knowing, product by product and version by version, exactly which components you ship and where they came from. That's a visibility problem before it's a reporting problem.
€15M
Max fine, or 2.5% of global turnover, for breaching Articles 13 & 14 or Annex I
24hr
Time to file an early warning once you become aware of active exploitation
72hr
Time to file a full notification with corrective measures taken so far
14d
Time to file a final report once a fix is available
Scope is broad
Connected devices, IoT/OT systems, industrial controllers, networking gear, medical devices, and standalone software, including legacy products already on the EU market.
Upstream obligations too
If you find a vulnerability in a third-party component, you must notify that component's own manufacturer or maintainer, not just your own customers.
Silence has consequences
If you don't notify affected users, the responsible CSIRT can step in and notify them directly, without you controlling the message.

Five moves, before the clock runs out.

None of this waits for December 2027. The September 2026 reporting deadline already applies to products on the market today.
Where the CRA lands first, and hardest.
The CRA's scope is horizontal, but the pressure lands hardest where connected products, long support periods, and regulated supply chains already meet. This is who we work with today.

Manufacturing
& Industrial

OT systems, industrial controllers, and connected equipment sold or deployed across the EU.

Medical Devices & Healthcare

Connected medical devices and health software, where SBOM rigor already overlaps with FDA expectations.

Telecom &
Networking

Network infrastructure and communications equipment with long field-support periods.

Software &
Technology Vendors

Standalone software and platform providers now facing a legal, not just best-practice, SBOM requirement.

Automotive & Connected Devices

Vehicle software and IoT-connected products carrying multi-year support obligations under the CRA.
Built for the people who carry the risk.
CyBeats is built for the leaders accountable for product security and compliance, giving them one SBOM System of Record to work from, not just the engineers running individual scans.
Product Security
Officer
Owns the SBOM program end to end; needs a single source of truth across every product and version.
CSO / Security
Leadership
Accountable for overall risk posture and reporting readiness ahead of regulatory deadlines.
Product Security & Governance Lead
Translates CRA obligations into repeatable process across product lines and release cycles.
Compliance &
Regulatory Affairs
Owns audit-ready documentation and defensible timelines when a regulator or customer asks for evidence.
From first call to CRA-ready.
1

Book a demo

OT systems, industA short call to understand your product portfolio and where your SBOM and reporting readiness stand today.rial controllers, and connected equipment sold or deployed across the EU.
2

Scope & assess

We map your products against CRA requirements and identify the fastest path to a compliant SBOM System of Record.
3

Onboard & ingest

Your SBOM System of Record is connected to your existing pipelines, ingesting and enriching SBOMs across your portfolio.
4

Monitor & report

Continuous vulnerability matching, with Raven's AI layer available as an optional add-on where speed and volume outpace your team.
See your CRA readiness gap in one call.
Book a demo and we'll walk through what compliance looks like for your specific product portfolio, before the September 2026 deadline.
Decorative graphic
Book a Demo
Visibility for the mandate.
Speed for the clock.
One governed record of your software. One AI layer that reasons through it at the speed the deadline demands.

SBOM System of Record

Powered by SBOM Studio
Your continuously governed inventory of every component you ship, generated and matched against live vulnerability data in CycloneDX and SPDX, benchmarked against standards like BSI TR-03183.
  • SBOM generation, ingestion & monitoring at scale
  • Continuous vulnerability lifecycle management, VEX & VDP
  • Built to answer "which products are affected" in minutes
Explore the SBOM System of Record

Project RAVEN

AI intelligence layer
Raven connects the AI coding agents your teams already use to your System of Record, assessing which vulnerabilities actually apply to your products, at a pace no manual review can match.
  • Surfaces applicable, exploitable vulnerabilities, just in time
  • Runs on your own AI tooling, no new agent to deploy
  • Built for teams racing a reporting deadline, not a backlog
Learn About Raven
The reporting clock starts September 11, 2026.
Let's find out where your product portfolio stands before it does.
Decorative graphic
Book a Demo
Speak the language regulators already do.

Software Bill of Materials

SBOM
A machine-readable inventory of the components in a product, the foundation the CRA's reporting and disclosure obligations sit on.

VEX

Vulnerability Exploitability eXchange
A statement of whether a known vulnerability in a component actually affects a given product, used alongside an SBOM rather than inside it.

Cyber Resilience Act

CRA / Regulation (EU) 2024/2847
The EU's horizontal cybersecurity law for products with digital elements, covering secure-by-design, SBOM, and vulnerability reporting obligations.

SBOM System of Record

CRA / Regulation (EU) 2024/2847
The EU's horizontal cybersecurity law for products with digital elements, covering secure-by-design, SBOM, and vulnerability reporting obligations.

Article 14 reporting

The CRA provision requiring manufacturers to report actively exploited vulnerabilities and severe incidents to ENISA and their national CSIRT, from Sept 11, 2026.

CE marking

The conformity mark confirming a product meets CRA requirements before it can be placed on the EU market.