Added to favorites
Removed from favorites
One Year Countdown to EU CRA Compliance - September 11, 2026, Changes Everything
The EU Cyber Resilience Act (CRA) imposes a critical deadline on September 11, 2026, when all manufacturers of products with digital elements, including software, IoT, OT, and embedded systems, must report any actively exploited vulnerabilities to ENISA within 24 hours, even for legacy products already on the market. While full CRA compliance begins in December 2027, reporting obligations come earlier, meaning vendors need SBOMs, continuous vulnerability monitoring, and automated exploitability analysis in place before September 2026 to avoid fines of up to €15M or 2.5% of global revenue. Keysight SBOM Manager enables vendors to prepare by providing accurate SBOM generation, vulnerability monitoring, compliance scoring, VEX templates, and secure SBOM sharing, ensuring organizations are CRA-ready ahead of the hidden deadline.