Sprita iT

Regulation (EU) 2024/2847

Cyber Resilience Act and SBOM

The Cyber Resilience Act sets cybersecurity requirements for products with digital elements placed on the EU market. Its first hard deadline is 11 September 2026, when the vulnerability and incident reporting obligations (Article 14) apply. It also requires secure-by-design properties, vulnerability handling across the support period, and a machine-readable software bill of materials covering at least top-level dependencies.

Next deadline11 September 2026

Vulnerability and incident reporting obligations (Article 14) apply — 24-hour early warning, 72-hour notification.

  1. 10 December 2024

    Regulation entered into force

  2. 11 June 2026

    Rules on conformity assessment bodies apply

  3. 11 September 2026

    Reporting obligations apply (Article 14)

  4. 11 December 2027

    Main body of requirements applies

Primary source: Regulation (EU) 2024/2847 on EUR-Lex · Last reviewed 14 August 2026

Who is in scope

  • Manufacturers of products with digital elements placed on the EU market — hardware and software
  • Importers and distributors, with their own verification duties
  • Organizations that materially modify a product, which can assume manufacturer obligations

Scope depends on your entity, sector and — for directives — national transposition. This page is informational, not legal advice.

What we produce

  • Machine-readable SBOM per release, generated in the pipeline
  • Vulnerability handling procedure and operating record
  • Security testing evidence across the product lifecycle
  • Technical documentation supporting conformity work

We produce technical evidence and control narratives. We do not certify your compliance — that remains with you and your auditors.

What it requires from software teams

01

Software bill of materials

Components must be identified and documented in a commonly used, machine-readable format covering at minimum the top-level dependencies. This is the requirement that makes continuous SBOM generation an engineering necessity rather than an audit exercise.

02

Vulnerability handling across the support period

Manufacturers must address vulnerabilities without delay during the defined support period, including providing security updates — an obligation that extends well past the release date.

03

Reporting obligations — live from 11 September 2026

From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting product security to ENISA and the relevant CSIRT — an early warning within 24 hours of awareness, a fuller notification within 72 hours, and a final report thereafter. This obligation (Article 14) applies well before the main body of requirements, which is why it is the first CRA deadline to plan for.

04

Secure by design and by default

Products must be made available with a secure configuration by default and designed to limit attack surface, with the manufacturer able to demonstrate conformity.

How Sprita iT Europe helps

  1. 1

    Establish continuous SBOM generation in CycloneDX or SPDX inside your build

  2. 2

    Assess product security properties against the essential requirements

  3. 3

    Design the vulnerability handling process that has to run for the whole support period

  4. 4

    Prepare the technical documentation trail conformity assessment depends on

Frequently asked questions

When do CRA obligations start to apply?

Application is staged. The Regulation entered into force on 10 December 2024. The rules on notification of conformity assessment bodies apply from 11 June 2026; the vulnerability and incident reporting obligations (Article 14) apply from 11 September 2026; and the main body of requirements applies from 11 December 2027. The reporting deadline is the first hard date most manufacturers face — and it is imminent.

Does the CRA apply to internal software we do not sell?

The regulation targets products with digital elements made available on the EU market. Purely internal software is a different question — but if you embed components in something you place on the market, or you materially modify a product, obligations can attach. Scope should be assessed product by product.

Is a one-off SBOM enough?

No. Dependencies change every release, so an inventory produced once for an audit describes a system that no longer exists. The workable approach is generating it in the pipeline so every build carries a current inventory.

Primary sources

We link legal texts and standards directly. This page is informational and is not legal advice; obligations depend on your entity, sector and national transposition.

Where do you stand against CRA?

A scoped assessment maps your estate to the obligations that actually apply to your entity — and produces the evidence trail.