The EU Cyber Resilience Act introduces a critical 24-hour window for software vendors to report exploited flaws. Companies must now prove exactly what software shipped and when vulnerabilities were discovered to avoid legal penalties.
- Software vendors must notify ENISA within 24 hours of discovering an actively exploited vulnerability.
- A comprehensive report must follow within 72 hours of the initial discovery.
- The reporting mandate begins September 11, 2026, while engineering requirements follow on December 11, 2027.
- Maintaining a real-time Software Bill of Materials (SBOM) is now a legal necessity, not just a compliance checkbox.
The landscape of software liability is shifting dramatically with the implementation of the EU Cyber Resilience Act (CRA). Starting September 11, 2026, the act transforms vulnerability disclosure from a voluntary 'best practice' into a strict legal obligation. For any manufacturer selling digital products within the European Union, the clock begins ticking the moment an actively exploited flaw is identified.
The immediate challenge is the narrow reporting window. Companies are required to notify the European Union Agency for Cybersecurity (ENISA) within 24 hours of learning about an active exploit. This is followed by a mandatory detailed report within 72 hours. For many organizations, this timeline is nearly impossible to meet without sophisticated, automated tracking of their software supply chain.
Why This Matters
BozokMedia analysis shows that the EU CRA creates a dangerous 'visibility gap.' Most companies treat their Software Bill of Materials (SBOM) as a static document generated during a specific audit period. However, the CRA demands current, living documentation. Since approximately 98% of modern applications rely on open-source components, the risk is systemic. If a company cannot identify exactly which version of a library shipped in which product, they cannot meet the 24-hour reporting deadline, exposing them to significant legal and financial risks.
The EU CRA is functionally a visibility requirement before it becomes a security requirement; knowing what you shipped is the only way to survive the 24-hour clock.
The disparity between reporting requirements and remediation speed is stark. While the law demands a 24-hour warning, industry data from Edgescan suggests that the average time to remediate a critical vulnerability is roughly 55 days. This creates a period of extreme vulnerability where a company has legally admitted to a flaw but has not yet patched it, potentially inviting further attacks.
To mitigate these risks, organizations are adopting two primary strategies. Some are investing in internal pipeline instrumentation to regenerate SBOMs automatically. Others are shifting toward curated, pre-vetted component catalogs to ensure provenance is established before the software ever enters the build process.
Historical Background
The EU CRA follows the precedent set by the US Executive Order 14028 in 2021, which first pushed for SBOMs among federal vendors. However, where the US order focused on procurement, the EU CRA focuses on market access and product safety, making it a broader regulatory hurdle for any global software vendor wishing to operate in the European market.
| Feature | US EO 14028 | EU Cyber Resilience Act (CRA) |
|---|---|---|
| Primary Focus | Federal Procurement | Market Access (EU Wide) |
| SBOM Requirement | Static/Point-in-time | Current/Dynamic (Article 13) |
| Reporting Window | Variable/Agency specific | Strict 24h (Initial) / 72h (Full) |
Frequently Asked Questions
1. What happens if a company fails to report a vulnerability within 24 hours?
Failure to comply with the reporting obligations of the EU CRA can lead to significant fines and potential restrictions on selling the affected digital product within the EU market.
2. When do the actual engineering and security requirements take effect?
While reporting starts in September 2026, the engineering requirements regarding how products are built and maintained apply from December 11, 2027.