LIVE SEPTEMBER 11, 2026

EU CRA SBOM and Article 14 Reporting Obligations, Built Into SBOM Studio

The EU Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, requires manufacturers selling products with digital elements into the EU to report actively exploited vulnerabilities within 24 hours from September 11, 2026, and to maintain a machine-readable SBOM from December 11, 2027.

SBOM Studio covers both: a governed SBOM System of Record, and Article 14 reports prepared for submission against the 24-hour clock.

You don't need another CRA explainer. You need to be ready.

December 10, 2024

Entered into force
The CRA became EU law. Transitional periods start.

September 11, 2026

Mandatory reporting (Article 14)
From September 11, 2026, actively exploited vulnerabilities and severe incidents must be reported to ENISA and your national CSIRT, including for products already on the market.

December 11, 2027

Full application (Annex I)
Essential cybersecurity requirements, SBOM obligations, conformity assessment, and CE marking all apply.

Not based in the EU? The CRA still applies.

Does the CRA apply if you're not headquartered in the EU? Yes. It follows where you sell, not where you're headquartered. If your product reaches EU customers, you carry the same SBOM and Article 14 reporting obligations.
Headquartered in the EU
The CRA applies in full: SBOM, secure-by-design, and Article 14 reporting.
Non-EU, selling into the EU
The CRA applies regardless of location. If your product connects to a network and reaches EU customers, the same obligations do.
Selling through EU distributors
The CRA applies to you first. Your distributors must verify CRA compliance and CE marking before they can sell your product.

Built for the teams carrying the risk.

Product Security Officers, CSOs, and product security and governance leaders are the ones accountable when a CRA deadline is missed. SBOM Studio gives them one governed SBOM System of Record and Article 14 reports ready to file, whether they're headquartered in the EU or selling into it.

Manufacturing
& Industrial

OT systems, industrial controllers, and connected equipment sold or deployed across the EU.

Internet of Things (IoT)

Connected consumer and industrial devices, often the least inventoried products in a portfolio.

Telecom &
Networking

Network infrastructure and communications equipment with long field-support periods.

Software &
Technology Vendors

Standalone software and platform providers now facing a legal, not just best-practice, SBOM requirement.

Automotive

Type-approved vehicles are excluded under 2019/2144. Aftermarket and non-type-approved components fall under the CRA.

Medical Devices

Devices fall under MDR and IVDR. Companion apps and non-device software fall under the CRA. All require an SBOM.

Five moves, before the clock runs out.

One system of record. One 24-hour clock.
The EU Cyber Resilience Act's technical requirements come down to two things, on two dates: Article 14 reporting from September 11, 2026, and a governed SBOM System of Record under Annex I from December 11, 2027.

SBOM Studio · System of Record

Most teams have SBOMs scattered across build pipelines, spreadsheets, and vendor emails. SBOM Studio unifies component- and project-level SBOMs into one governed product SBOM, in the machine-readable formats regulators require. It's continuously maintained across your portfolio and matched against live vulnerability data.

A governed product SBOM satisfies Annex I, Part II(1) of the CRA, which applies from December 11, 2027, and it's what a market surveillance authority can request while your product is supported.
CycloneDX
SPDX
EU CRA Annex I
BSI TR-03183-2
CISA 2026 Minimum Elements
Explore SBOM Studio

Raven · Add-on

Raven confirms whether the vulnerable path can execute in your build, returns a reasoned VEX statement, and lands the evidence in your audit trail. That's how you report inside 24 hours.
Explore Raven
Raven, the AI intelligence layer add-on to SBOM Studio
BE READY BY SEPTEMBER 11, 2026

SBOM Studio Prepares Your Article 14 Report

Article 14 of the EU Cyber Resilience Act requires manufacturers to notify ENISA and their national CSIRT of an actively exploited vulnerability within 24 hours of becoming aware of it.

SBOM Studio continuously matches every component in your SBOM against threat intelligence, KEV listings, exploitation markers, and patch status. It flags a vulnerability only on reliable evidence of malicious exploitation in your product, not a theoretical weakness or exploitation elsewhere. That moment of awareness starts your Article 14 clock, and SBOM Studio begins your reporting workflow immediately.

Your report is mapped field-for-field to the ENISA Single Reporting Platform (SRP), pre-assembled and ready for you to review and file, not drafted from scratch.

Article 14 also covers severe incidents affecting product security, on a separate clock. This feature covers Actively Exploited Vulnerabilities (AEV).
Decorative graphic
Book a Demo

The CRA isn't your only SBOM mandate.

The EU CRA, EU MDR, FDA §524B, IEC 62443, NIS2, ISO/SAE 21434, and the 2026 SBOM Minimum Elements all ask for the same underlying thing: a component inventory you can prove. The Cybeats regulations tracker maps SBOM and vulnerability management requirements across industries and jurisdictions, filterable by country and sector, with links to the official sources.
Explore the Regulations Tracker
EU CRA Glossary

Software Bill of Materials

A software bill of materials (SBOM) is a machine-readable inventory of the components in a product, typically in CycloneDX or SPDX format. It's the foundation that the CRA's reporting and disclosure obligations sit on.

Actively exploited vulnerability

An actively exploited vulnerability is a vulnerability with reliable evidence of exploitation in the wild against a specific product. Under the CRA, this is the trigger that starts the 24-hour Article 14 reporting clock.

Cyber Resilience Act

The Cyber Resilience Act, Regulation (EU) 2024/2847, is the EU's horizontal cybersecurity law for products with digital elements, covering secure-by-design, SBOM, and vulnerability reporting obligations.

SBOM System of Record

An SBOM System of Record is the single, governed, audit-ready source of truth for every SBOM across a product portfolio, matched continuously against vulnerability data. Distinct from a generation tool, which describes one build, or a repository, which stores files.

Article 14 reporting

Article 14 is the CRA provision requiring manufacturers to report actively exploited vulnerabilities and severe incidents to ENISA and their national CSIRT, from September 11, 2026. Early warning within 24 hours, detailed notification within 72 hours, final report within 14 days of a corrective or mitigating measure becoming available. Severe incidents follow a separate clock, with a final report within one month.

CE marking

CE marking is the conformity mark confirming a product meets CRA requirements before it can be placed on the EU market.

Frequently Asked Questions

What is the EU Cyber Resilience Act (CRA)?

The EU's first horizontal cybersecurity law for products with digital elements. It sets secure-by-design requirements, an SBOM obligation, and rules for reporting actively exploited vulnerabilities, and entered into force December 10, 2024.

When does EU CRA reporting start?

Article 14 reporting obligations take effect September 11, 2026. From that date, actively exploited vulnerabilities and severe incidents must be reported to ENISA and your national CSIRT within 24 hours of becoming aware of them.

Who does the EU CRA apply to?

Manufacturers, importers, and distributors of connected products sold into the EU, regardless of where the company is based, including legacy products already on the market.

What are the penalties for EU CRA non-compliance?

Penalties depend on which obligation is breached. For failures to meet the essential cybersecurity requirements in Annex I, including SBOM and vulnerability handling obligations, fines can reach up to €15 million or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher. Other breaches carry lower ceilings. Confirm your exposure with counsel.

What is Article 14 of the EU CRA?

The provision requiring manufacturers to report actively exploited vulnerabilities and severe incidents, on a staged clock: a 24-hour early warning, a 72-hour full notification, and a final report once a fix is available.

Does the EU CRA apply to products already on the market?

Yes. The September 11, 2026 reporting deadline applies to products already sold into the EU, not only new releases, well ahead of the full application date in December 2027.

What is an SBOM and why does the CRA require one?

A machine-readable inventory of every component in a software product. The CRA requires a current, per-product, per-version SBOM so you can tell within minutes whether a new vulnerability affects you, a prerequisite for the 24-hour clock.

How is SBOM Studio different from a generic SBOM generator?

SBOM generation is one step. SBOM Studio pairs it with continuous vulnerability monitoring and AEV, a built-in reporting feature mapped field-for-field to the ENISA SRP, so it's an ongoing SBOM System of Record, not a one-time export.

Does SBOM Studio help with software supply chain security beyond the EU CRA?

Yes. The same governed SBOM System of Record, continuous monitoring, and VEX generation that meet EU CRA obligations also support FDA Section 524B, IEC 62443, and other frameworks, so CRA readiness builds on infrastructure you can reuse elsewhere.