One Year Countdown to EU CRA Compliance - September 11, 2026, Changes Everything
Most organizations believe they have until 11 December 2027 to comply with the EU Cyber Resilience Act (CRA). That assumption is dangerously wrong. The real first deadline is 11 September 2026, exactly one year from today. From that date forward, all manufacturers of products with digital elements shipped to the EU, including software, IoT devices, OT systems, medical equipment, networking gear, and embedded systems, are required to report actively exploited vulnerabilities within 24 hours to ENISA and designated national CSIRTs. This applies even to legacy products you shipped years ago. And here’s the kicker:
If you don’t have SBOMs and a vulnerability management process in place before September 2026, you cannot comply.
The CRA’s Overlooked Obligation: Vulnerability Reporting
The Cyber Resilience Act introduces the most far-reaching cybersecurity reporting framework Europe has ever seen. At its core, article 14 establishes a mandatory obligation for manufacturers to report actively exploited vulnerabilities in their products:
Article 14(1)
“A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator … and to ENISA.”
Read Article 14
This isn’t optional. This isn’t “best effort.” This is a legal obligation, and the timeline is strict:
Applies to All Products - Even Legacy Ones
Most vendors assume these reporting obligations apply only to new products released after CRA enforcement. That’s incorrect. Article 69(3) makes this clear:
“By way of derogation from paragraph 2, the obligations laid down in Article 14 shall apply to all products with digital elements … that have been placed on the market before 11 December 2027.”
Read Article 69
This is critical. It doesn’t matter if your product shipped in 2015 or 2025. If the product is still on the market and an exploitable vulnerability emerges, you must detect it and report it, starting 11 September 2026.
The Practical Problem: You Can’t Report What You Don’t Know
Imagine this scenario:
- On October 2026 CISA adds a critical OpenSSL vulnerability to the Known Exploited Vulnerabilities (KEV) catalog.
- Your IoT gateway, released in 2019, uses the vulnerable OpenSSL version.
- If that vulnerability is exploitable in your product, you must report the following:
- Within 24 hours:
- The existence of an actively exploited vulnerability in your product
- Which product(s), model(s), version(s) are affected
- The Member States where the product is available, if known
- Within 72 hours:
- General nature of the exploit and of the vulnerability (as known)
- Product details as above if not already provided
- Corrective or mitigating measures taken or planned
- Measures users can take
- Sensitivity classification of the notification, if applicable
- Within 14 days:
- Description of the vulnerability, including severity and impact
- If available, info about any malicious actor(s) who have exploited or are exploiting it
- Details of the security update or other corrective measures released
- Within 24 hours:
But here’s the problem. If you don’t have a complete SBOM for that product and real-time vulnerability monitoring, you won’t even know whether your product is affected. By the time you manually investigate, the 24-hour clock has expired, and you’re in non-compliance.
The Implicit Deadline for SBOMs is 11 September 2026
The CRA explicitly requires vendors to create SBOMs, as outlined in Annex I, Part II:
“Manufacturers shall identify and document vulnerabilities and components contained in products, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at least the top-level dependencies.”
Read Annex I
Technically, SBOM obligations don’t become enforceable until 11 December 2027. But here’s the hidden dependency most vendors are missing:
Reporting obligations start 11 September 2026. To report, you must know exactly which components exist in your products. To know that, you need SBOMs and automated vulnerability tracking as from September 2026. In practice, SBOM readiness is mandatory at least 15 months before the official CRA SBOM deadline.
Actively Exploited Vulnerabilities
CRA’s reporting obligations are not triggered by every CVE. They apply only when the vulnerability is being actively exploited in the wild.
To comply, you must continuously monitor:
- CISA Known Exploited Vulnerabilities (KEV)
- ENISA advisories (EUVD)
- CVE/NVD databases
- Vendor advisories
And you must automatically correlate these feeds with your SBOMs to:
- Identify affected products instantly
- Determine exploitability
- Trigger a 24-hour reporting workflow
Without automation, this is impossible at scale.
The CRA Penalties Are Massive
Ignoring the September 2026 reporting obligation isn’t just risky; it can also be costly.
For many vendors, a single failure could cost more than the cost of full CRA readiness.
Today Is September 11, 2025. You Have Exactly 365 Days Left
If you wait until 2027 to prepare, you’ll already be non-compliant for over a year.
How Keysight SBOM Manager Solves This
Preparing for CRA compliance requires end-to-end capabilities, and Keysight SBOM Manager is uniquely positioned to deliver them:
- Accurate SBOM Generation
- Generates high-fidelity SBOMs directly from binaries, no source code needed.
- Ensures full visibility into third-party, proprietary, and open-source components.
- Continuous Vulnerability Monitoring
- Automatically tracks vulnerabilities across NVD, CISA KEV catalog, Github advisories, OSV DB, etc.
- Instantly correlates vulnerabilities with your SBOMs.
- Delivers real-time alerts when new vulnerabilities affect your products.
- Comprehensive SBOM Management
- SBOM ingestion & aggregation.
- SBOM scoring for compliance.
- SBOM auto-correction & enrichment.
- VEX Template Support
- Provides ready-to-use VEX template in industry-standard format.
- Simplifies CRA reporting by giving manufacturers the tools to communicate exploitability clearly.
- Secure SBOM & Vulnerability Sharing
- Share SBOMs and vulnerability reports securely with regulators and customers.
- Includes granular access controls for secure collaboration.
Final Call to Action
Today is September 11, 2025. On September 11, 2026, the EU will begin enforcing CRA vulnerability reporting obligations. You now have exactly one year to:
- Build SBOMs for every product you sell
- Deploy continuous vulnerability monitoring
- Implement reporting workflows
- Be prepared for 24-hour ENISA notifications
Keysight SBOM Manager is the all-in-one platform that helps you:
- Generate accurate SBOMs at scale
- Continuously monitor vulnerabilities
- Detect exploitable vulnerabilities
- Securely share SBOMs and vulnerability reports
- Be CRA-ready ahead of the hidden September 2026 deadline
The CRA clock is ticking. Compliance isn’t optional but Keysight SBOM Manager makes it achievable.