One Year Countdown to EU CRA Compliance - September 11, 2026, Changes Everything

Most organizations believe they have until 11 December 2027 to comply with the EU Cyber Resilience Act (CRA). That assumption is dangerously wrong. The real first deadline is 11 September 2026, exactly one year from today. From that date forward, all manufacturers of products with digital elements shipped to the EU, including software, IoT devices, OT systems, medical equipment, networking gear, and embedded systems, are required to report actively exploited vulnerabilities within 24 hours to ENISA and designated national CSIRTs. This applies even to legacy products you shipped years ago. And here’s the kicker:
If you don’t have SBOMs and a vulnerability management process in place before September 2026, you cannot comply.

The CRA’s Overlooked Obligation: Vulnerability Reporting

The Cyber Resilience Act introduces the most far-reaching cybersecurity reporting framework Europe has ever seen. At its core, article 14 establishes a mandatory obligation for manufacturers to report actively exploited vulnerabilities in their products:

Article 14(1)
“A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator … and to ENISA.”
Read Article 14

This isn’t optional. This isn’t “best effort.” This is a legal obligation, and the timeline is strict:

Applies to All Products - Even Legacy Ones

Most vendors assume these reporting obligations apply only to new products released after CRA enforcement. That’s incorrect. Article 69(3) makes this clear:

“By way of derogation from paragraph 2, the obligations laid down in Article 14 shall apply to all products with digital elements … that have been placed on the market before 11 December 2027.”
Read Article 69

This is critical. It doesn’t matter if your product shipped in 2015 or 2025. If the product is still on the market and an exploitable vulnerability emerges, you must detect it and report it, starting 11 September 2026.

The Practical Problem: You Can’t Report What You Don’t Know

Imagine this scenario:

But here’s the problem. If you don’t have a complete SBOM for that product and real-time vulnerability monitoring, you won’t even know whether your product is affected. By the time you manually investigate, the 24-hour clock has expired, and you’re in non-compliance.

The Implicit Deadline for SBOMs is 11 September 2026

The CRA explicitly requires vendors to create SBOMs, as outlined in Annex I, Part II:

“Manufacturers shall identify and document vulnerabilities and components contained in products, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at least the top-level dependencies.”
Read Annex I

Technically, SBOM obligations don’t become enforceable until 11 December 2027. But here’s the hidden dependency most vendors are missing:

Reporting obligations start 11 September 2026. To report, you must know exactly which components exist in your products. To know that, you need SBOMs and automated vulnerability tracking as from September 2026. In practice, SBOM readiness is mandatory at least 15 months before the official CRA SBOM deadline.

Actively Exploited Vulnerabilities

CRA’s reporting obligations are not triggered by every CVE. They apply only when the vulnerability is being actively exploited in the wild.

To comply, you must continuously monitor:

And you must automatically correlate these feeds with your SBOMs to:

Without automation, this is impossible at scale.

The CRA Penalties Are Massive

Ignoring the September 2026 reporting obligation isn’t just risky; it can also be costly.

For many vendors, a single failure could cost more than the cost of full CRA readiness.

Today Is September 11, 2025. You Have Exactly 365 Days Left

If you wait until 2027 to prepare, you’ll already be non-compliant for over a year.

How Keysight SBOM Manager Solves This

Preparing for CRA compliance requires end-to-end capabilities, and Keysight SBOM Manager is uniquely positioned to deliver them:

Final Call to Action

Today is September 11, 2025. On September 11, 2026, the EU will begin enforcing CRA vulnerability reporting obligations. You now have exactly one year to:

Keysight SBOM Manager is the all-in-one platform that helps you:

The CRA clock is ticking. Compliance isn’t optional but Keysight SBOM Manager makes it achievable.

limit
3