CRA · Product & Supplier Compliance
Products with digital elements: reporting obligations from 11.09.2026 under control, product register linked to suppliers.
The Cyber Resilience Act isn't only for manufacturers of standalone software.
The Cyber Resilience Act (Regulation (EU) 2024/2847) applies to virtually every product with digital elements placed on the EU market — from IoT devices and industrial controllers to standalone software. The reporting obligations under Art. 14 already apply from 11.09.2026, well ahead of the full application of the remaining obligations (CE conformity, technical documentation, SBOM) from 11.12.2027 — anyone who starts preparing only in 2027 misses the first deadline.
Two clocks run in parallel and are easy to confuse under time pressure: an actively exploited vulnerability must be reported as an early warning within 24 hours and as a full notification within 72 hours to the coordinating CSIRT and ENISA (Art. 14(1)–(4)); a severe incident affecting product security follows the same rhythm but has its own content requirements (Art. 14(5)–(8)). Without dedicated tooling, this runs on emails and improvised templates — exactly where things get missed under time pressure.
Then there's the supply chain: anyone integrating third-party components — including open source — must track their suppliers' security requirements (Art. 13(5)–(6)) and maintain a machine-readable software bill of materials (SBOM) per product. What matters is one register that serves classification, the reporting clock, vulnerability management, and supplier linkage from a single data set — instead of four separate spreadsheets reassembled before every audit.
Six building blocks for today's reporting obligations and CE conformity from 2027.
Product register with CRA classification (Annex III/IV)
Every product with digital elements is captured and classified under Annex III (important products, class I/II) or Annex IV (critical products) — with a traceable rationale instead of a gut call.
Reporting clock 24h / 72h to CSIRT/ENISA
Actively exploited vulnerabilities and severe incidents run a visible countdown from detection for the early warning, notification, and final report — split by reporting reason, with the fields each stage requires.
Vulnerability management & coordinated disclosure
A coordinated-disclosure policy with a fixed point of contact and a log of every vulnerability handled across the full support period — evidence instead of an ad-hoc process.
SBOM per product (CycloneDX/SPDX)
A machine-readable software bill of materials per product, covering at least the top-level dependencies — importable instead of maintained by hand, and linked directly to the product register.
Supplier flow-down to the vendor register
Security requirements for suppliers — including integrated open-source components — are tracked from the same vendor register that also serves DORA and NIS2, instead of being maintained separately.
Technical documentation & support-period tracking
The support period per product (at least 5 years, unless the expected usage period is shorter) and the technical documentation under Annex VII are tracked alongside it — the foundation for CE conformity assessment from 11.12.2027.
More about the CRA and the infrastructure behind it.
How supplier flow-down and concentration-risk analysis build on the same register.
Feature details →How vendor registry, security ratings, and risk assessment work together.
Feature details →