SBOM Guide

Cyber Resilience Act (CRA)

What the EU Cyber Resilience Act requires, with a focus on SBOM and vulnerability reporting.

  • The CRA in brief

    The CRA has applied in part since 11 September 2026 and applies in full from 11 December 2027. This page covers which products are in scope, the dates, what manufacturers must do and the penalties.

  • SBOM requirements in the CRA

    The CRA requires manufacturers to draw up an SBOM for every product with digital elements. This page covers what the regulation requires, what it leaves open, and how to prepare before 11 December 2027.

  • Vulnerability reporting under the CRA

    Manufacturers must report actively exploited vulnerabilities and severe incidents within 24 hours through ENISA's Single Reporting Platform. This page covers what to report, the deadlines and what you need in place.