ActiveState

Under the EU CRA, one question decides whether you keep access to the EU market:

Can you prove what's inside your product?

The majority of modern products are open source code your team didn't write. Under the EU CRA, security teams must prove exactly what's inside of them and that every package is accounted for, on demand.

EU CRA's Article 14 reporting obligations take effect on September 11, 2026, ahead of the full compliance deadline in December 2027. They require manufacturers to report actively exploited vulnerabilities and severe incidents on all products on the market, not just new releases. The reporting is time-boxed: a 24 hour early warning, a 72 hour full notification, and a 14 day final report once a corrective measure is available, filed to your national CSIRT through the ENISA Single Reporting Platform.

This reflects our current understanding of EU CRA and is not legal advice. Confirm scope and applicability for your products with your legal team.

Under the EU CRA, a critical vulnerability in your product creates four obligations. Scanner tooling alone can't cover them.

EU CRA Incident Console / Incidents / INC-4410
Critical vulnerability CVE-2026-3391 Report readiness: 0 of 4 fields complete
EU CRA required field
Product and component affected
No match
System of record SBOM manager

No confirmed match for this component in current inventory.

EU CRA required field
Date identified
Not logged
System of record SIEM · Monitoring

First detection timestamp not logged in ticket.

EU CRA required field
Action taken
Unsigned
System of record Change mgmt · CM-4410

Signed off by: — unsigned —

EU CRA required field
Time to resolution
Still open
System of record SLA tracker

9 of 14 remediation days used. Still open.

Day 9 of 14

A 24-hour clock starts the moment you become aware of a vulnerability in your product

Miss it, and you risk EU CRA enforcement action.

Most teams don't maintain a record of every component in their product. Under the EU CRA, that gap becomes a 24-hour deadline. Miss the window on an actively exploited vulnerability, and a market surveillance authority can restrict EU sales of the product for the duration of an investigation, on a timeline you don't set and can't shorten.

EU CRA is enforced by national market surveillance authorities, who can require products to be brought into compliance, restrict their availability, or order withdrawal or recall from the EU market. Financial penalties alone can reach a ceiling of €15M or 2.5% of worldwide annual turnover, whichever is higher, though actual outcomes depend on the nature and duration of the infringement and regulatory discretion.

For most organizations, the market access exposure (sales restricted while an investigation runs) is the more immediate consequence than the fine, because the timeline sits with the regulator and is unknown. The EU CRA also raises the bar on product liability: a product that was non-compliant at the time of a breach and used as an attack vector is materially harder to defend.

The €15M figure is a legal maximum. This is not legal advice. Confirm your exposure with legal counsel.

Where would your team actually stand?

Nearly all of your EU CRA exposure comes back to open source.

The EU CRA asks for four things your program must have.

Own triage the moment an upstream maintainer or advisory discloses a vulnerability in a component you depend on. An auditor will ask who's accountable at each stage, and whether that's written down anywhere.

Prove what's running today, not just what your team chose at the last major release, using a machine-readable SBOM (formats like SPDX or CycloneDX are common) covering your direct dependencies. However, 64% of open source in production lives one layer deeper, in transitive dependencies, which is usually where an exploited vulnerability actually turns up.

Commit to a support period as a budget decision, made before a vulnerability forces it. That includes components whose maintainers stop patching before your product reaches end of life. Security updates for the product's expected lifetime need to be budgeted and defensible on the record, not improvised once something breaks.

Define what's reportable before the clock starts. That means knowing which upstream disclosures actually reach your dependency tree, not discovering it only after the 24-hour reporting window has already started.

The EU CRA is sector-neutral and applies based on market access, not headquarters location: if your connected software products reach EU users, you are likely in scope regardless of where your company is based.

Legal Disclaimer: The information provided is for general informational purposes only and is not intended as legal, financial, or professional advice. You should not act upon any information without seeking professional counsel. We make no representations or warranties of any kind, express or implied, about the completeness, accuracy, reliability, or availability of the information.

'Scan and pray' programs can't meet this bar.
Secure by design is what's next.

The ActiveState Curated Catalog is what makes that possible

Talk to an expert

Software inventory

Every open source component is built from source with cryptographic attestation. Provenance is producible on demand.

Inventory · SBOM manager09:12
No confirmed match in current inventory.
Product / componentNo match
Confirmed match — 12+ languages covered.
Product / componentVerified

Continuous monitoring

Disclosures are monitored for and announced as soon as they’re public.

Monitoring · SIEM09:12
First detection timestamp not logged.
Date identifiedNot logged
Detected and timestamped — 09:12.
Date identifiedLogged

Change control

Every fix contains an auditable record of what was done and when.

Change managementCM-4410
No signed remediation record on file.
Action takenUnsigned
Remediation signed and on file.
Action takenSigned

Remediation SLA

Remediation runs on a 5 business-day SLA for Critical CVEs, against 54-day industry average. A timeline you can plan on.

SLA tracker · CRA reportingSLA · Critical
9 of 14 remediation days used. Still open.
Day 9 of 14Still open
Resolved — Day 3 of 5.
Day 3 of 5Resolved

Only vetted, policy-aligned components enter your product in the first place, through the tools your team already uses, including their AI coding agents. The open source software in your product is accounted for before a question ever arrives.

Talk to our team today to see exactly where the ActiveState Curated Catalog fits your environment, and how it addresses your EU CRA obligations.