Scope and role come first

Regulation (EU) 2024/2847 covers products with digital elements made available on the EU market whose intended or reasonably foreseeable use includes a direct or indirect data connection. Scope includes qualifying remote data processing, but is not a blanket rule for every SaaS service. Article 2 excludes, among others, products covered by the EU medical-device and in-vitro diagnostic-device regulations.

Source: EUR-Lex · Regulation (EU) 2024/2847 · Articles 2–3.

The Commission’s implementation material provides further orientation on manufacturers, open-source activity and connected services. Document the particular product, commercial distribution and operator role before selecting an obligation profile.

Source: European Commission · CRA legislative summary.

Application dates and reporting now

MilestoneDateStatus on October 4, 2026
Entry into forceDecember 10, 2024Regulation in force.
Conformity-assessment-body provisionsJune 11, 2026Already applicable.
Manufacturer Article 14 reportingSeptember 11, 2026Already applicable.
Broader CRA applicationDecember 11, 2027Future application date.

Source: European Commission · CRA implementation.

For manufacturers, reportable actively exploited vulnerabilities and severe incidents follow early-warning and notification deadlines of 24 and 72 hours after awareness. Final-report timing differs: vulnerability reports follow availability of a corrective measure; severe-incident reports follow the notification. Open-source stewards have a different application timeline. Review the reporting guidance for the exact conditions and exceptions.

Source: European Commission · CRA reporting obligations.

The Single Reporting Platform is operational. Organizations need a reporting decision and escalation path today; the later broad application date does not defer Article 14.

Source: ENISA · Single Reporting Platform FAQs.

Creation, access and disclosure are different decisions

Maintain a controlled inventory tied to each supported product release. Prepare to produce technical evidence through the applicable authority process. Separately define what component and security information customers receive under user-information expectations and contractual terms.

Do not equate authenticated customer access, regulator access and public distribution. They have different recipients and confidentiality concerns. A disclosure policy can support legitimate vulnerability response while protecting non-public architecture and private software details.

Practical manufacturer controls

ControlEvidence to retain
Product scope decisionProduct description, market, connected functionality and exclusions considered.
Release-bound inventoryArtifact identifier, format/version, generation context and quality results.
Supplier coverageUpstream inventories, gaps and documented follow-up.
Vulnerability handlingAdvisory intake, applicability decisions, owners and response records.
Reporting decisionAwareness evidence, escalation and report history where applicable.
Documentation retrievalTest export of a selected release and associated evidence.

These are implementation recommendations. Assign responsibilities among product engineering, security, regulatory and legal teams. Rehearse a newly discovered issue in a third-party component and verify who determines applicability, who authorizes reporting and who communicates with customers.

Guidance and standards still need status checks

The Commission published implementation guidance in July 2026. It helps explain scope and lifecycle questions and is separate from the binding regulation. This build verified the official overview and reporting pages; the guidance download endpoint was rate-limited, so detailed guidance-only interpretations are deliberately excluded.

Source: European Commission · Cyber Resilience Act.

Before a conformity decision, check applicable implementing acts, harmonized standards and Official Journal citations. A published SBOM format standard is not, by itself, proof that a product meets all CRA requirements. Keep future schema changes separate from present reporting obligations.

Primary sources