The EU Cyber Resilience Act (CRA) is approaching. While full compliance obligations don't take effect until 2027, the reporting obligations for actively exploited vulnerabilities take effect from September 2026. For many manufacturers of products with embedded software, this means: only six months remain to build the necessary processes.
What Applies from September 2026
Manufacturers must report actively exploited vulnerabilities in their products to ENISA within 24 hours. A more detailed report follows within 72 hours, and a complete analysis with remediation measures after 14 days.
What This Means in Practice
- Vulnerability Management: You need continuous CVE monitoring for all software components of your products
- SBOM as Foundation: Without a current Software Bill of Materials, you won't know which components are affected
- Processes and Responsibilities: Who reports? To whom? In what format? These questions must be answered now
- Technical Infrastructure: Automated alerts and prepared reporting forms save valuable hours in an emergency
Full CRA Obligation from 2027
From 2027, additional requirements apply: Security by Design, complete technical documentation, secure update mechanisms, and mandatory conformity assessment. Non-compliant products may no longer be sold in the EU – with fines of up to EUR 15 million.
Our Offering
proofnet supports manufacturers with a comprehensive CRA compliance package: automated firmware analysis, SBOM generation, continuous CVE monitoring, and ready-made compliance reports. Learn more or request a free CRA assessment directly.