Software Bills of Materials, explained for product teams.
The EU Cyber Resilience Act is not just an automotive rule. It applies to almost any product with digital elements placed on the EU market, which means most connected devices. Here is a practical readiness checklist.
If your product has software and reaches a network or another device, assume the CRA applies and confirm the detail later. It shifts responsibility for security onto the manufacturer for the product's whole supported lifetime, not just the point of sale.
The dates that matter
Two milestones drive the plan: from September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents; from December 2027, the full set of obligations applies and non-compliant products can no longer be placed on the market. Treat 2027 as the hard gate and 2026 as when your vulnerability-handling process has to be live.
The readiness checklist
- Secure by design. A documented risk assessment behind your design decisions.
- SBOM. A maintained Software Bill of Materials for every product.
- Vulnerability handling. A working process to receive, triage, fix and disclose issues across the support period.
- Conformity assessment. The right route for your product class, internal control for most, a third party for critical classes.
- Reporting. A channel and procedure to meet the 2026 reporting duties.
Where to start
Scope which products fall in, then stand up the SBOM pipeline and vulnerability-handling process first, they take longest to make real, before working the conformity route.
A prioritised plan turns a broad regulation into manageable steps. A compliance gap assessment is the place to begin.