Software Bills of Materials, explained for product teams.
The EU Cyber Resilience Act (CRA) sets mandatory cybersecurity requirements for products with digital elements. Full enforcement begins in December 2027, with reporting duties from September 2026, so the real work starts now.
If your product connects to a network or another device, the CRA almost certainly applies to it. The regulation is broad by design: it covers the software and hardware placed on the EU market, and it shifts responsibility for security onto the manufacturer for the whole supported lifetime of the product, not just at the point of sale.
What the 2027 deadline actually means
Two dates matter. From September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents. From December 2027, the full set of obligations applies and non-compliant products can no longer be placed on the EU market. Treat 2027 as the hard gate and 2026 as the moment your vulnerability-handling process has to be live.
The core obligations, in plain terms
- Secure by design. Security has to be built in from the start, with a risk assessment behind your design decisions.
- An SBOM. Maintain a Software Bill of Materials so you can see and disclose what is inside your product.
- Vulnerability handling. A working process to receive, triage, fix and disclose vulnerabilities across the support period.
- Conformity assessment. Demonstrate conformity, for most products via internal control, for critical classes via a third party.
The CRA rewards teams that already treat security as a lifecycle activity. If you bolt it on at the end, the conformity step is where that shows.
A practical path to readiness
Start with a gap assessment: scope which of your products fall in scope, map each obligation to what you already do, and surface what is missing. From there, stand up an SBOM pipeline and a vulnerability-handling process first, they take the longest to make real, then work the conformity route for your product class.
None of this needs to happen at once. A prioritised plan, mapped to your product and markets, turns a daunting regulation into a sequence of manageable steps, and that is exactly where a compliance gap assessment earns its place.