By clicking "Accept all cookies", you agree to storing cookies on your device to enhance site navigation, analyze site usage and assist in our marketing efforts as outlined in our privacy policy.
By clicking 'Accept all cookies', you agree to storing cookies on your device to enhance site navigation, analyze site usage and assist in our marketing efforts as outlined in our privacy policy.
EU CRA SBOM and Article 14 Reporting Obligations, Built Into SBOM Studio
The EU Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, requires manufacturers selling products with digital elements into the EU to report actively exploited vulnerabilities within 24 hours from September 11, 2026, and to maintain a machine-readable SBOM from December 11, 2027.
SBOM Studio covers both: a governed SBOM System of Record, and Article 14 reports prepared for submission against the 24-hour clock.
You don't need another CRA explainer. You need to be ready.
December 10, 2024
Entered into force
The CRA became EU law. Transitional periods start.
September 11, 2026
Mandatory reporting (Article 14)
From September 11, 2026, actively exploited vulnerabilities and severe incidents must be reported to ENISA and your national CSIRT, including for products already on the market.
December 11, 2027
Full application (Annex I)
Essential cybersecurity requirements, SBOM obligations, conformity assessment, and CE marking all apply.
Not based in the EU? The CRA still applies.
Does the CRA apply if you're not headquartered in the EU? Yes. It follows where you sell, not where you're headquartered. If your product reaches EU customers, you carry the same SBOM and Article 14 reporting obligations.
Headquartered in the EU
The CRA applies in full: SBOM, secure-by-design, and Article 14 reporting.
Non-EU, selling into the EU
The CRA applies regardless of location. If your product connects to a network and reaches EU customers, the same obligations do.
Selling through EU distributors
The CRA applies to you first. Your distributors must verify CRA compliance and CE marking before they can sell your product.
Built for the teams carrying the risk.
Product Security Officers, CSOs, and product security and governance leaders are the ones accountable when a CRA deadline is missed. SBOM Studio gives them one governed SBOM System of Record and Article 14 reports ready to file, whether they're headquartered in the EU or selling into it.
Manufacturing & Industrial
OT systems, industrial controllers, and connected equipment sold or deployed across the EU.
Internet of Things (IoT)
Connected consumer and industrial devices, often the least inventoried products in a portfolio.
Telecom & Networking
Network infrastructure and communications equipment with long field-support periods.
Software & Technology Vendors
Standalone software and platform providers now facing a legal, not just best-practice, SBOM requirement.
Automotive
Type-approved vehicles are excluded under 2019/2144. Aftermarket and non-type-approved components fall under the CRA.
Medical Devices
Devices fall under MDR and IVDR. Companion apps and non-device software fall under the CRA. All require an SBOM.
Five moves, before the clock runs out.
1
Map your product portfolio
Every product reaching the EU market, including legacy products still in the field, and confirm which exemptions may apply.
2
Get a real SBOM, per product, per version
Machine-readable, current, and detailed enough to answer "are we affected" in minutes, not weeks.
3
Automate vulnerability matching
Continuous matching between your SBOMs and live vulnerability intelligence, so exploited CVEs surface against the right products immediately.
4
Design your reporting workflow now
Know who owns the 24-hour early warning, how you'll register with the CRA Single Reporting Platform, and your escalation path.
5
Publish a disclosure policy
A coordinated vulnerability disclosure policy and a public security contact, as required under Annex I.
One system of record. One 24-hour clock.
The EU Cyber Resilience Act's technical requirements come down to two things, on two dates: Article 14 reporting from September 11, 2026, and a governed SBOM System of Record under Annex I from December 11, 2027.
SBOM Studio · System of Record
Most teams have SBOMs scattered across build pipelines, spreadsheets, and vendor emails. SBOM Studio unifies component- and project-level SBOMs into one governed product SBOM, in the machine-readable formats regulators require. It's continuously maintained across your portfolio and matched against live vulnerability data.
A governed product SBOM satisfies Annex I, Part II(1) of the CRA, which applies from December 11, 2027, and it's what a market surveillance authority can request while your product is supported.
Raven confirms whether the vulnerable path can execute in your build, returns a reasoned VEX statement, and lands the evidence in your audit trail. That's how you report inside 24 hours.
Article 14 of the EU Cyber Resilience Act requires manufacturers to notify ENISA and their national CSIRT of an actively exploited vulnerability within 24 hours of becoming aware of it.
SBOM Studio continuously matches every component in your SBOM against threat intelligence, KEV listings, exploitation markers, and patch status. It flags a vulnerability only on reliable evidence of malicious exploitation in your product, not a theoretical weakness or exploitation elsewhere. That moment of awareness starts your Article 14 clock, and SBOM Studio begins your reporting workflow immediately.
Your report is mapped field-for-field to the ENISA Single Reporting Platform (SRP), pre-assembled and ready for you to review and file, not drafted from scratch.
Article 14 also covers severe incidents affecting product security, on a separate clock. This feature covers Actively Exploited Vulnerabilities (AEV).
The EU CRA, EU MDR, FDA §524B, IEC 62443, NIS2, ISO/SAE 21434, and the 2026 SBOM Minimum Elements all ask for the same underlying thing: a component inventory you can prove. The Cybeats regulations tracker maps SBOM and vulnerability management requirements across industries and jurisdictions, filterable by country and sector, with links to the official sources.
A software bill of materials (SBOM) is a machine-readable inventory of the components in a product, typically in CycloneDX or SPDX format. It's the foundation that the CRA's reporting and disclosure obligations sit on.
Actively exploited vulnerability
An actively exploited vulnerability is a vulnerability with reliable evidence of exploitation in the wild against a specific product. Under the CRA, this is the trigger that starts the 24-hour Article 14 reporting clock.
Cyber Resilience Act
The Cyber Resilience Act, Regulation (EU) 2024/2847, is the EU's horizontal cybersecurity law for products with digital elements, covering secure-by-design, SBOM, and vulnerability reporting obligations.
SBOM System of Record
An SBOM System of Record is the single, governed, audit-ready source of truth for every SBOM across a product portfolio, matched continuously against vulnerability data. Distinct from a generation tool, which describes one build, or a repository, which stores files.
Article 14 reporting
Article 14 is the CRA provision requiring manufacturers to report actively exploited vulnerabilities and severe incidents to ENISA and their national CSIRT, from September 11, 2026. Early warning within 24 hours, detailed notification within 72 hours, final report within 14 days of a corrective or mitigating measure becoming available. Severe incidents follow a separate clock, with a final report within one month.
CE marking
CE marking is the conformity mark confirming a product meets CRA requirements before it can be placed on the EU market.
Frequently Asked Questions
What is the EU Cyber Resilience Act (CRA)?
The EU's first horizontal cybersecurity law for products with digital elements.
It sets secure-by-design requirements, an SBOM obligation, and rules for reporting
actively exploited vulnerabilities, and entered into force December 10, 2024.
When does EU CRA reporting start?
Article 14 reporting obligations take effect September 11, 2026.
From that date, actively exploited vulnerabilities and severe incidents must be
reported to ENISA and your national CSIRT within 24 hours of becoming aware of them.
Who does the EU CRA apply to?
Manufacturers, importers, and distributors of connected products sold into the EU,
regardless of where the company is based, including legacy products already on the market.
What are the penalties for EU CRA non-compliance?
Penalties depend on which obligation is breached. For failures to meet
the essential cybersecurity requirements in Annex I, including SBOM
and vulnerability handling obligations, fines can reach up to €15 million
or 2.5% of total worldwide annual turnover for the preceding financial year,
whichever is higher. Other breaches carry lower ceilings. Confirm your exposure with counsel.
What is Article 14 of the EU CRA?
The provision requiring manufacturers to report actively exploited vulnerabilities and
severe incidents, on a staged clock: a 24-hour early warning, a 72-hour full notification,
and a final report once a fix is available.
Does the EU CRA apply to products already on the market?
Yes. The September 11, 2026 reporting deadline applies to products already sold into the EU,
not only new releases, well ahead of the full application date in December 2027.
What is an SBOM and why does the CRA require one?
A machine-readable inventory of every component in a software product. The CRA requires a current,
per-product, per-version SBOM so you can tell within minutes whether a new vulnerability affects you,
a prerequisite for the 24-hour clock.
How is SBOM Studio different from a generic SBOM generator?
SBOM generation is one step. SBOM Studio pairs it with continuous vulnerability monitoring and AEV,
a built-in reporting feature mapped field-for-field to the ENISA SRP, so it's an ongoing
SBOM System of Record, not a one-time export.
Does SBOM Studio help with software supply chain security beyond the EU CRA?
Yes. The same governed SBOM System of Record, continuous monitoring, and VEX generation that meet
EU CRA obligations also support FDA Section 524B, IEC 62443, and other frameworks,
so CRA readiness builds on infrastructure you can reuse elsewhere.