Regulation (EU) 2024/2847 · reporting duties since 11 September 2026
The CRA makes you answerable for code you did not write.
Placing a connected product on the market means owning the third-party libraries and supplied components inside it. The software bill of materials is not a document but an inventory you keep.
The Cyber Resilience Act covers products with digital elements – machine controls, connected instruments, software itself. It requires security by design, vulnerability management across the support period and a machine-readable software bill of materials.
The timeline is staggered. Since 11 September 2026 the Article 14 reporting duty applies to actively exploited vulnerabilities and severe incidents, staged over 24 hours, 72 hours and a final report. Full requirements including conformity assessment apply from 11 December 2027.
Who is affected
- Manufacturers of connected products placed on the EU market – including those based in Switzerland or Liechtenstein.
- Importers and distributors with their own verification duties.
- Component and software suppliers: without your SBOM your customer cannot complete theirs.
- Providers of open-source components in a commercial context, with reliefs.
What matters for the supply chain
- Art. 13
- Due diligence when integrating third-party components: you must assess their security posture.
- SBOM
- A machine-readable bill of materials, maintained continuously rather than produced once.
- Art. 14
- Reporting of actively exploited vulnerabilities: early warning within 24 hours to CSIRT and ENISA.
- Support
- Security updates across the promised period – which must line up with your suppliers’ commitments.
- Contract
- Reporting routes, response times and SBOM delivery belong in supplier contracts, not in hope.
How SCRM covers it
Component suppliers as records
Who supplies which building block, with what support commitment and which security contact.
Commitments with expiry
If a supplier’s support ends before yours, a gap opens – visible before it bites.
Reporting chain on file
Contacts and deadlines where they will be searched for in minutes.
Incidents per supplier
A cluster around one component is a sourcing argument, not an IT detail.
Frequently asked
We are a Swiss manufacturer. Does the CRA apply?
Once you make products available on the EU market, yes – market access decides, not your registered seat. It does not apply directly to the Swiss domestic market, but customer requirements carry it there.
How hard is the 24-hour deadline for small companies?
The duty itself is unchanged. Following a 2025 corrigendum, micro and small enterprises are not fined for missing that first deadline alone.
Is an SBOM per release enough?
The point is answering “which products contain this vulnerable component” in minutes. An SBOM produced only at release does not answer it.
As of July 2026. Not legal advice.