The majority of modern products are open source code your team didn't write. Under the EU CRA, security teams must prove exactly what's inside of them and that every package is accounted for, on demand.
EU CRA's Article 14 reporting obligations take effect on September 11, 2026, ahead of the full compliance deadline in December 2027. They require manufacturers to report actively exploited vulnerabilities and severe incidents on all products on the market, not just new releases. The reporting is time-boxed: a 24 hour early warning, a 72 hour full notification, and a 14 day final report once a corrective measure is available, filed to your national CSIRT through the ENISA Single Reporting Platform.
This reflects our current understanding of EU CRA and is not legal advice. Confirm scope and applicability for your products with your legal team.
Most teams don't maintain a record of every component in their product. Under the EU CRA, that gap becomes a 24-hour deadline. Miss the window on an actively exploited vulnerability, and a market surveillance authority can restrict EU sales of the product for the duration of an investigation, on a timeline you don't set and can't shorten.
Where would your team actually stand?