---
title: "Cyber Resilience Act (CRA): dates and duties for manufacturers | Edge SDN"
description: "What the Cyber Resilience Act asks manufacturers of products with digital elements: 24-hour reporting since 11 September 2026, SBOM and security updates from 11 December 2027, fines. With links to each article."
url: https://www.edge-sdn.com/regulations/cyber-resilience-act/
last_updated: 2026-09-30
---

Regulation (EU) 2024/2847

# Prepare your products for the Cyber Resilience Act

Last updated 30 September 2026. A summary, not legal advice. Always check the official text for your case.

What does the CRA ask a manufacturer?

Every product with digital elements sold in the EU must be secure by design. Since 11 September 2026 the manufacturer must report actively exploited vulnerabilities within 24 hours, also for products already sold. From 11 December 2027 it also needs an SBOM, vulnerability handling and free security updates for the whole support period.

Reporting duty applies[Article 71(2)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847#art%5F71)

The CRA applies in full[Article 71(2)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847#art%5F71)

Early warning of an actively exploited vulnerability[Article 14(2)(a)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847#art%5F14)

Or 2.5% of worldwide turnover, whichever is higher[Article 64(2)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847#art%5F64)

Who is covered

## Anyone who puts a product with digital elements on the EU market

Manufacturers, importers and distributors of hardware and software that connects to a device or a network. The manufacturer carries most of the duties.

Since 11 September 2026

## Report an actively exploited vulnerability in three steps

The same deadlines apply to a severe incident, with a final report one month after the notification. Reports go to the national CSIRT and to ENISA through the single reporting platform.

1. **Early warning within 24 hours**From the moment you become aware of it.
2. **Notification within 72 hours**The product, the exploit and the measures users can take.
3. **Final report within 14 days**After a fix or a mitigation is available.

[Article 14(2) and 14(4)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847#art%5F14)

[Article 14(8)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847#art%5F14)

[Article 69(3)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847#art%5F69)

From 11 December 2027

## Build every new product to the essential requirements

- No known exploitable vulnerabilities when the product is made available [Annex I, Part I(2)(a)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847#anx%5FI)
- An SBOM in a commonly used, machine-readable format, at least of the top-level dependencies [Annex I, Part II(1)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847#anx%5FI)
- Vulnerability handling for the whole support period, at least five years [Article 13(8)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847#art%5F13)
- Security updates without delay and free of charge, unless agreed otherwise for a tailor-made product [Annex I, Part II(8)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847#anx%5FI)
- A policy on coordinated vulnerability disclosure [Annex I, Part II(5)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847#anx%5FI)
- Technical documentation and EU declaration of conformity for 10 years or the support period, whichever is longer [Article 13(13)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847#art%5F13)

**What the CRA does not ask**

Products placed on the market before 11 December 2027 must meet these requirements only if they are substantially modified afterwards ([Article 69(2)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847#art%5F69)). The reporting duty covers them anyway.

### What to do first

- List your products and the software inside each one
- Decide who receives and sends a report within 24 hours
- Start the SBOM for one product
- Set up a way to reach the users of each delivered product

You sign the declaration of conformity. We prepare the evidence: which delivered product is exposed, what to tell the customer and what you did.

[Demo](https://www.edge-sdn.com/demo/)

Our products

## Which products help, and why

Built for it

### Shield Lifecycle

SBOM, vulnerability handling and VEX for every delivered product, Article 14 reports, customer notices and documentation.

Article 13, Article 14, Annex I

[Explore Shield Lifecycle](https://www.edge-sdn.com/products/shield-lifecycle/)

Helps with a part

### Edge Shield

Reduces the attack surface of the product.

Annex I, Part I, 2(j)

[Explore Edge Shield](https://www.edge-sdn.com/products/edge-shield/)

FAQ

## Questions about the CRA

### Does the CRA apply to products I sold before December 2027?

The reporting duty of Article 14 does, since 11 September 2026. The other requirements apply to those products only if they are substantially modified from 11 December 2027 ([Article 69](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847#art%5F69)).

### Is a machine a product with digital elements?

A machine with a PLC, an HMI or a remote access gateway contains software and connects to a device or a network. So it is a product with digital elements, and its manufacturer has the duties of the CRA.

### Who receives the 24-hour report?

The CSIRT designated as coordinator in the Member State of your main establishment, and ENISA at the same time, through the single reporting platform ([Article 14](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847#art%5F14)).

### How long is the support period?

At least five years, unless the product is expected to be in use for less. It must reflect how long the product is expected to be in use ([Article 13(8)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847#art%5F13)).

### Can a small company be fined for a late report?

Micro and small enterprises cannot be fined for missing the 24-hour early warning ([Article 64(10)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847#art%5F64)). The duty to report still applies to them.

## Where are you against 20 January 2027?

Seven questions about how you work today. Three minutes. You get a score out of 10 and what is missing for you.

Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026
