Scope and role come first
Regulation (EU) 2024/2847 covers products with digital elements made available on the EU market whose intended or reasonably foreseeable use includes a direct or indirect data connection. Scope includes qualifying remote data processing, but is not a blanket rule for every SaaS service. Article 2 excludes, among others, products covered by the EU medical-device and in-vitro diagnostic-device regulations.
Source: EUR-Lex · Regulation (EU) 2024/2847 · Articles 2–3.
The Commission’s implementation material provides further orientation on manufacturers, open-source activity and connected services. Document the particular product, commercial distribution and operator role before selecting an obligation profile.
What the legal text says about SBOMs
Annex I, Part II(1) specifies a commonly used, machine-readable format covering at least top-level dependencies. Article 13(24) allows implementing acts to specify format and elements. Annex VII(8) addresses SBOM inclusion in technical documentation following a reasoned authority request where necessary to check conformity. These provisions do not require automatic public release of the entire SBOM.
Source: EUR-Lex · Regulation (EU) 2024/2847 · Annex I, Part II(1); Article 13(24); Annex VII(8).
Application dates and reporting now
| Milestone | Date | Status on October 4, 2026 |
|---|---|---|
| Entry into force | December 10, 2024 | Regulation in force. |
| Conformity-assessment-body provisions | June 11, 2026 | Already applicable. |
| Manufacturer Article 14 reporting | September 11, 2026 | Already applicable. |
| Broader CRA application | December 11, 2027 | Future application date. |
Source: European Commission · CRA implementation.
For manufacturers, reportable actively exploited vulnerabilities and severe incidents follow early-warning and notification deadlines of 24 and 72 hours after awareness. Final-report timing differs: vulnerability reports follow availability of a corrective measure; severe-incident reports follow the notification. Open-source stewards have a different application timeline. Review the reporting guidance for the exact conditions and exceptions.
Source: European Commission · CRA reporting obligations.
The Single Reporting Platform is operational. Organizations need a reporting decision and escalation path today; the later broad application date does not defer Article 14.
Creation, access and disclosure are different decisions
Maintain a controlled inventory tied to each supported product release. Prepare to produce technical evidence through the applicable authority process. Separately define what component and security information customers receive under user-information expectations and contractual terms.
Do not equate authenticated customer access, regulator access and public distribution. They have different recipients and confidentiality concerns. A disclosure policy can support legitimate vulnerability response while protecting non-public architecture and private software details.
Practical manufacturer controls
| Control | Evidence to retain |
|---|---|
| Product scope decision | Product description, market, connected functionality and exclusions considered. |
| Release-bound inventory | Artifact identifier, format/version, generation context and quality results. |
| Supplier coverage | Upstream inventories, gaps and documented follow-up. |
| Vulnerability handling | Advisory intake, applicability decisions, owners and response records. |
| Reporting decision | Awareness evidence, escalation and report history where applicable. |
| Documentation retrieval | Test export of a selected release and associated evidence. |
These are implementation recommendations. Assign responsibilities among product engineering, security, regulatory and legal teams. Rehearse a newly discovered issue in a third-party component and verify who determines applicability, who authorizes reporting and who communicates with customers.
Guidance and standards still need status checks
The Commission published implementation guidance in July 2026. It helps explain scope and lifecycle questions and is separate from the binding regulation. This build verified the official overview and reporting pages; the guidance download endpoint was rate-limited, so detailed guidance-only interpretations are deliberately excluded.
Source: European Commission · Cyber Resilience Act.
Before a conformity decision, check applicable implementing acts, harmonized standards and Official Journal citations. A published SBOM format standard is not, by itself, proof that a product meets all CRA requirements. Keep future schema changes separate from present reporting obligations.
Primary sources
- EUR-Lex · Regulation (EU) 2024/2847Binding EU regulation
- European Commission · CRA legislative summaryOfficial legal-text summary
- European Commission · Cyber Resilience ActOfficial implementation overview
- European Commission · CRA implementationImplementation timeline
- European Commission · CRA reporting obligationsAgency implementation guidance
- ENISA · Single Reporting Platform FAQsOperational reporting guidance