By clicking "Accept all cookies", you agree to storing cookies on your device to enhance site navigation, analyze site usage and assist in our marketing efforts as outlined in our privacy policy.
By clicking 'Accept all cookies', you agree to storing cookies on your device to enhance site navigation, analyze site usage and assist in our marketing efforts as outlined in our privacy policy.
From September 11, 2026, manufacturers selling into the EU must report actively exploited vulnerabilities within 24 hours, or face fines up to €15 million. Here's what the EU Cyber Resilience Act requires, and how CyBeats gets you ready before the clock starts.
Applies to products already on the EU market, not just new releases.
Early warning
24 hours
Full notification
72 hours
Final report
14 days
CyBeats does not provide legal advice. This page is for general information only. Confirm how the CRA applies to your specific products with qualified legal counsel.
The rules changed. Compliance is no longer optional.
The EU's first horizontal cybersecurity law for products with digital elements: a legal mandate for a governed SBOM System od Record on every product, and a strict clock for reporting actively exploited vulnerabilities once they're found.
It reaches manufacturers, importers, and distributors regardless of where they're based. If your product connects to a network and reaches an EU customer, you're in scope.
At a Glance
Regulation
(EU) 2024/2847
Entered into force
Dec 10, 2024
SBOM format
CycloneDX/SPDX
Reporting platform
ENISA SRP
Regulation
15M/2.5% turnover
Three dates. One of them is closer than you think.
DEC 10, 2024
Entered into force
The CRA becomes EU law. The phased compliance clock starts.
SEP 11, 2026
Reporting obligations live
Article 14: actively exploited vulnerabilities and severe incidents must be reported to ENISA and your national CSIRT, on a 24-hour clock.
Reporting obligations live
DEC 11, 2027
Full CRA application
Essential cybersecurity requirements, SBOM obligations, conformity assessment, and CE marking all apply.
This reaches further than most teams expect.
Reporting a vulnerability within 24 hours means knowing, product by product and version by version, exactly which components you ship and where they came from. That's a visibility problem before it's a reporting problem.
€15M Max fine, or 2.5% of global turnover, for breaching Articles 13 & 14 or Annex I
24hr
Time to file an early warning once you become aware of active exploitation
72hr
Time to file a full notification with corrective measures taken so far
14d
Time to file a final report once a fix is available
Scope is broad
Connected devices, IoT/OT systems, industrial controllers, networking gear, medical devices, and standalone software, including legacy products already on the EU market.
Upstream obligations too
If you find a vulnerability in a third-party component, you must notify that component's own manufacturer or maintainer, not just your own customers.
Silence has consequences
If you don't notify affected users, the responsible CSIRT can step in and notify them directly, without you controlling the message.
Five moves, before the clock runs out.
1
Map your product portfolio
Every product reaching the EU market, including legacy products still in the field, and confirm which exemptions may apply.
2
Get a real SBOM, per product, per version
Every product reaching the EU market, including legacy products still in the field, and confirm which exMachine-readable, current, and detailed enough to answer "are we affected" in minutes, not weeks.emptions may apply.
3
Automate vulnerability matching
Continuous matching between your SBOMs and live vulnerability intelligence, so exploited CVEs surface against the right products immediately.
4
Design your reporting workflow now
Continuous matKnow who owns the 24-hour early warning, how you'll register with the CRA Single Reporting Platform, and your escalation path.ching between your SBOMs and live vulnerability intelligence, so exploited CVEs surface against the right products immediately.
5
Publish a disclosure policy
A coordinated vulnerability disclosure policy and a public security contact, as required under Annex I.
None of this waits for December 2027. The September 2026 reporting deadline already applies to products on the market today.
Where the CRA lands first, and hardest.
The CRA's scope is horizontal, but the pressure lands hardest where connected products, long support periods, and regulated supply chains already meet. This is who we work with today.
Manufacturing & Industrial
OT systems, industrial controllers, and connected equipment sold or deployed across the EU.
Medical Devices & Healthcare
Connected medical devices and health software, where SBOM rigor already overlaps with FDA expectations.
Telecom & Networking
Network infrastructure and communications equipment with long field-support periods.
Software & Technology Vendors
Standalone software and platform providers now facing a legal, not just best-practice, SBOM requirement.
Automotive & Connected Devices
Vehicle software and IoT-connected products carrying multi-year support obligations under the CRA.
Built for the people who carry the risk.
CyBeats is built for the leaders accountable for product security and compliance, giving them one SBOM System of Record to work from, not just the engineers running individual scans.
Product Security Officer
Owns the SBOM program end to end; needs a single source of truth across every product and version.
CSO / Security Leadership
Accountable for overall risk posture and reporting readiness ahead of regulatory deadlines.
Product Security & Governance Lead
Translates CRA obligations into repeatable process across product lines and release cycles.
Compliance & Regulatory Affairs
Owns audit-ready documentation and defensible timelines when a regulator or customer asks for evidence.
From first call to CRA-ready.
1
Book a demo
OT systems, industA short call to understand your product portfolio and where your SBOM and reporting readiness stand today.rial controllers, and connected equipment sold or deployed across the EU.
2
Scope & assess
We map your products against CRA requirements and identify the fastest path to a compliant SBOM System of Record.
3
Onboard & ingest
Your SBOM System of Record is connected to your existing pipelines, ingesting and enriching SBOMs across your portfolio.
4
Monitor & report
Continuous vulnerability matching, with Raven's AI layer available as an optional add-on where speed and volume outpace your team.
See your CRA readiness gap in one call.
Book a demo and we'll walk through what compliance looks like for your specific product portfolio, before the September 2026 deadline.
One governed record of your software. One AI layer that reasons through it at the speed the deadline demands.
SBOM System of Record
Powered by SBOM Studio
Your continuously governed inventory of every component you ship, generated and matched against live vulnerability data in CycloneDX and SPDX, benchmarked against standards like BSI TR-03183.
Raven connects the AI coding agents your teams already use to your System of Record, assessing which vulnerabilities actually apply to your products, at a pace no manual review can match.
Surfaces applicable, exploitable vulnerabilities, just in time
Runs on your own AI tooling, no new agent to deploy
Built for teams racing a reporting deadline, not a backlog
A machine-readable inventory of the components in a product, the foundation the CRA's reporting and disclosure obligations sit on.
VEX
Vulnerability Exploitability eXchange
A statement of whether a known vulnerability in a component actually affects a given product, used alongside an SBOM rather than inside it.
Cyber Resilience Act
CRA / Regulation (EU) 2024/2847
The EU's horizontal cybersecurity law for products with digital elements, covering secure-by-design, SBOM, and vulnerability reporting obligations.
SBOM System of Record
CRA / Regulation (EU) 2024/2847
The EU's horizontal cybersecurity law for products with digital elements, covering secure-by-design, SBOM, and vulnerability reporting obligations.
Article 14 reporting
The CRA provision requiring manufacturers to report actively exploited vulnerabilities and severe incidents to ENISA and their national CSIRT, from Sept 11, 2026.
CE marking
The conformity mark confirming a product meets CRA requirements before it can be placed on the EU market.