---
title: EU CRA Readiness — ActiveState
description: Unaudited open source is now a market access risk under the EU CRA. See what's required by September 11, 2026, and December 2027.
---

[![ActiveState](https://go.activestate.com/hubfs/activestate-logo-1.png)](https://www.activestate.com)

[For Security Teams](https://go.activestate.com/eu-cra-readiness-for-security-teams-activestate) [For Engineering Teams](https://go.activestate.com/eu-cra-readiness-for-engineering-teams-activestate) Contact Us

[For Security Teams](https://go.activestate.com/eu-cra-readiness-for-security-teams-activestate) [For Engineering Teams](https://go.activestate.com/eu-cra-readiness-for-engineering-teams-activestate) Contact Us

# Under the EU CRA, unvetted open source can mean a market access risk, not just a security gap.

Your digital products run on open source software your team didn't write, and the EU CRA asks for diligence and attestation that it is secure. While AI helps your developers code faster, it pulls in open source packages without oversight. Since September 11, 2026, the EU CRA requires reporting of actively exploited vulnerabilities in your digital products sold in the EU. December 11, 2027, is the deadline for full compliance that determines market access. Non-compliance can put your EU market access at risk.

Talk to an expert

## [![](https://go.activestate.com/hubfs/EU%20CRA%20Microsite/icon-security-blue.svg) What the EU CRA expects from security teams Start here](https://go.activestate.com/eu-cra-readiness-for-security-teams-activestate)

Download the security readiness assessment

## [![](https://go.activestate.com/hubfs/EU%20CRA%20Microsite/icon-engineering-blue.svg) How the EU CRA impacts engineering teams Start here](https://go.activestate.com/eu-cra-readiness-for-engineering-teams-activestate)

Download the engineering readiness assessment

### Engineering owns the data

OSS governance has always been an engineering problem, and the EU CRA put a deadline on it that's already on your roadmap.

Since September 11, 2026, the reporting clock has been running for actively exploited vulnerabilities in your digital products offered in the EU. Teams can file that report in time by already knowing what's in their products, without having to figure it out after the fact.

Most SBOM processes today only capture direct dependencies. But 64% of your open source is transitive, not chosen directly, and that's exactly where an exploited vulnerability is likely to surface.

A governed OSS inventory, current SBOM coverage, and an audit trail for every remediation decision are due in full, for any product offered on the EU market, by the EU CRA's December 11, 2027 compliance deadline, and become ongoing overhead on every release after that, indefinitely.

![Developer time today vs. with ActiveState: up to 30% capacity reclaimed](https://go.activestate.com/hubfs/EU%20CRA%20Microsite/pasted-1784563904284-0.png)

![Package provenance: signed SBOM, cryptographic signature, full build provenance, and license compliance for every artifact](https://go.activestate.com/hubfs/EU%20CRA%20Microsite/pasted-1784563966941-0.png)

### Security owns the deadline

Security teams are handed the EU CRA's reporting and documentation obligations, but meeting them depends on engineering work: a current, accurate component inventory, a documented remediation workflow, and audit-ready provenance records, none of which engineering has been formally asked to prioritize before. Your organization needs a defined process that survives an audit, not a business practice that relies on individual memory.

The EU CRA requires a documented vulnerability handling workflow covering intake, triage, remediation, and disclosure that can be demonstrated to a regulator.

The 24-hour and 72-hour reporting windows have been live since September 11, 2026, and meeting them is only realistic if you already know what's in your product before a disclosure happens.

The EU CRA requires an answer scanners aren’t built to provide: What was in your product? When did you know? What did you do? And how long did it take?

## The EU CRA makes it a shared obligation between Security and Engineering

Meeting the EU CRA's compliance demands is what protects your organization's EU market access.

54 days

Industry average for critical CVE remediation.

[Source: Edgescan 2026](https://www.edgescan.com/stats-report/)

60%

of breaches exploit a known, already-patched vulnerability.

[Source: Verizon DBIR 2026](https://datawater.com/verizon-dbir-2026-vulnerability/)

64%

of open source components in production are transitive, and your team didn't choose them directly.

[Source: Black Duck OSSRA 2025](https://www.blackduck.com/blog/managing-transitive-dependencies-open-source-software.html)

## Employing a Curated Catalog

The ActiveState Curated Catalog aligns Security and Engineering on a single EU CRA compliance effort. It gives you a private, pre-vetted source of open source software, so fewer vulnerabilities ever reach your build in the first place. Security teams get full provenance and mitigated exposure. Engineering teams stop pausing sprints for security work.

![Curated Catalog: vetted, built-from-source packages flowing into your existing tools](https://go.activestate.com/hubfs/EU%20CRA%20Microsite/pasted-1784326006750-0.png)

Automated, current SBOMs across every build

Cryptographic attestation and verifiable provenance for every component

5-day Critical CVE remediation SLA  
10 days for Highs, 30 for all others

## [![](https://go.activestate.com/hubfs/EU%20CRA%20Microsite/icon-security-blue.svg) What the EU CRA requires from security teams Start here](https://go.activestate.com/eu-cra-readiness-for-security-teams-activestate)

Take the security readiness assessment

## [![](https://go.activestate.com/hubfs/EU%20CRA%20Microsite/icon-engineering-blue.svg) How the EU CRA impacts engineering teams Start here](https://go.activestate.com/eu-cra-readiness-for-engineering-teams-activestate)

Take the engineering readiness assessment

## Explore CRA Further

### [AI Coding and Open Source Risk: What the Data Actually Shows About Remediation Debt Watch Webinar](https://youtu.be/IYpXS5bkJv0)

### [Blog Cyber Resilience Open Source Governance A rebrand to "cyber resilience" means nothing without re-architecture. Read more](https://www.activestate.com/blog/cyber-resilience-open-source-governance)

### [Blog Open Source Compliance Now Has a Deadline. Accountability Now Has a Name. The shift toward personal accountability. Read more](https://securityboulevard.com/2026/07/open-source-compliance-now-has-a-deadline-accountability-now-has-a-name/)

### [Blog EU Cyber Resilience Act (EU CRA) Compliance: Key Deadlines and Secure Container Strategies The container and SBOM angle. Read more](https://www.activestate.com/blog/eu-cyber-resilience-act-and-secure-open-source-and-containers)

## FAQ

Does the EU CRA apply to us if we're not headquartered in the EU?

Market access decides scope, not headquarters. If your connected products reach EU users, directly, through partners or resellers, or via cloud delivery, the EU CRA is likely relevant to you regardless of where your company is based. This is not legal advice; confirm applicability to your specific products with your legal team.

What's the difference between the September 11, 2026 obligations and the December 11, 2027 deadline?

Article 14 reporting, covering actively exploited vulnerabilities and severe incidents on products already on the market, has been in force since September 11, 2026. December 11, 2027 is the full compliance deadline. You'll be asked to provide a technical documentation file, a machine-readable SBOM, a defined security update support period, and a secure-by-design architecture, backed by conformity assessment.

Our products are already on the EU market. Doesn't the transitional provision cover us?

It's narrower than it looks. It applies only to products placed on the market before December 11, 2027 that don't later undergo a substantial modification, and a significant security-relevant update can count as one. It also doesn't touch Article 14 reporting, which already applies to products on the market regardless of when they were placed there. Confirm your applicability with legal counsel.

Does using ActiveState make our products EU CRA compliant?

Compliance is a legal determination made by your organization, informed by your own counsel. ActiveState provides a governed, pre-vetted open source supply chain: cryptographic provenance, current SBOMs, and defined remediation SLAs. These are the pieces of the technical documentation file that are otherwise difficult to build and keep current.

What actually happens if we're found non-compliant?

Market surveillance authorities have three tools available and can use them independently: financial penalties up to €15M or 2.5% of global annual turnover, product withdrawal, and sales restriction for the duration of an investigation. For most organizations, the market access risk, an unknown timeline you don't control, is the more immediate concern than the fine.

We just finished NIS2, SOC 2, or ISO 27001. Isn't this already covered?

Those frameworks cover related but different ground. None of them require a technical documentation file, SBOM coverage down to transitive dependencies, or a conformity assessment against secure-by-design requirements at the level of detail the EU CRA does.

Where should we start if we don't know where we stand?

Start with whichever side of the problem is live for you right now: security teams can take the EU CRA Security Readiness Assessment, and engineering teams can take the EU CRA Engineering Readiness Assessment.

This reflects our current understanding of EU CRA and is not legal advice. Confirm scope and applicability for your products with your legal team.

© 2026 ActiveState Software Inc. All rights reserved. ActiveState®, ActivePerl®, ActiveTcl®, ActivePython®, Komodo®, ActiveGo™, ActiveRuby™, ActiveNode™, ActiveLua™, and The Open Source Languages Company™ are all trademarks of ActiveState.

[Legal](https://www.activestate.com/eulas) [Privacy Policy](https://www.activestate.com/company/privacy-policy) [Accessibility](https://www.activestate.com/accessibility)