The European Union (EU) Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for software and hardware products sold in the EU, covering security by design, vulnerability handling, and ongoing maintenance obligations across the total product life cycle.
Beginning September 11, 2026, the CRA enters into an enforcement phase requiring manufacturers, importers, and distributors, to notify ENISA and designated national CSIRTs of actively exploited vulnerabilities and severe security incidents.
Is your organization ready to meet CRA vulnerability reporting requirements? Our helpful checklist can help you prepare.
In-Scope Products
The CRA defines a product classification system that includes a default category for all software as well as stringent classifications
based on primary product functions. It provides exclusions for products covered under alternative European cybersecurity or product
safety regulations, such as the Medical Device Regulation or EU 2019/2144 for automotive safety. Penalties for nonconformance
include fines that are a percentage of an organization’s global revenue and potential removal of the PDE from the European market.
Products covered by the CRA include
- Products that contain software or firmware, or standalone software that is required for a connected product to function
- Products that are commercially distributed in the EU (free open source software without commercial activity is generally excluded)
- Products that are not already subject to specified industry-specific regulations
- Products already on the European market are in scope; the CRA requirements are not limited to new releases
Mandatory Reporting Timelines
The reporting timelines include
- 24 hours: Manufacturers must file early warning of an actively exploited vulnerability or incident impacting SaaS or cloud
components of a PDE within 24 hours of the manufacturer becoming aware of such an event, via the single reporting platform (SRP)
provided by ENISA. - 72 hours: Manufacturers must provide a more detailed notification within 72 hours of becoming aware of an exploited vulnerability
within their PDE that includes a description of the vulnerability, its impact, what corrective measures are being taken, and what
mitigations a customer might take. This notification requirement includes vulnerabilities within integrated third-party components
and incidents due to an active exploit impacting SaaS or cloud components supporting a PDE’s operation. - 14 days: Manufacturers must provide a final report within 14 days after remediation becomes available covering the severity of
the incident, the impact of the vulnerability, lessons learned, and process improvements. A full root cause analysis is also required
for incidents impacting SaaS or cloud components of a PDE; this analysis deadline is one month after submitting the incident
notification.
Reporting capabilities must be operational and tested before September 2026.
SBOM Requirements
Software Bills of Materials (SBOMS) must
- Cover direct dependencies for every PDE placed on the European market, including product updates
- Be stored for potential review by market surveillance authorities
There is no requirement to share SBOMs with any third parties other than market surveillance authorities.
Continuous Vulnerability Monitoring
Manufacturers, distributors, and importers of PDEs should implement a continuous vulnerability monitoring process that can identify
potential changes in software supply chain risk, as communicated via the European Vulnerability Database (EUVD) or other data
sources as defined by the European Commission.
- Monitoring tools should prioritize potentially exploitable vulnerabilities but must also include integrated third-party components,
including open source libraries. - Manufacturers must monitor all products placed on the European market for the duration of the PDE’s support period. For products
containing integrated components from third parties, manufacturers must notify regulators and customers about exploitable
vulnerabilities in those components
Reporting Infrastructure
Manufacturers must file reports of actively exploited vulnerabilities via the SRP, and provide relevant details as defined by ENISA.
Internal policies and playbooks must account for and describe vulnerability and incident reporting over the total product life cycle,
including product support periods.
All cybersecurity decision-making must be documented, including tooling selection, vulnerability triage and disposition, scope of
affected products, and external communications.