The EU CRA’s Real Question: What Shipped, and When Did You Know?

As of September 11, 2026, software vendors selling digital products into the European Union will be required to notify the EU’s cybersecurity agency, ENISA, within 24 hours of learning that a vulnerability in their product is being actively exploited. This is just the beginning – by December 2027, companies must also prove that they’ve built and maintained their products securely.

The EU Cyber Resilience Act (CRA) is not just about compliance; it’s about transparency and accountability in software development. For years, open source maintainers have informally answered the question of “what shipped, and when did we first know there was a problem with it.” Now, companies across the board will be asked to do the same.

The challenge lies in knowing what actually shipped – not just what was produced at some point in time. The CRA requires software bills of materials (SBOMs) that are current, not stale documents generated under deadline pressure. With 98% of applications containing open source components, nearly every manufacturer selling into the EU must answer this question.

But here’s the rub: most teams don’t have a reliable way to keep their SBOMs up-to-date. The average time to remediate a high or critical application vulnerability is around 55 days, according to Edgescan’s 2026 Vulnerability Statistics Report. This gap between early warning and full notification clock will live in the EU CRA enforcement.

This means organizations must have tools and processes in place to keep their SBOMs current, not just generate them once under pressure. Companies will need to be able to track changes to their software components and dependencies over time, ensuring that their SBOMs reflect what’s actually running today.

The industry has been warned about this gap for some time now. When the US issued Executive Order 14028 in 2021, requiring software bills of materials from federal vendors, many organizations struggled to generate accurate and current SBOMs under deadline pressure. The EU CRA is more explicit than its predecessor, and companies would do well to take it seriously.

As we head into this new era of transparency and accountability, one thing is clear: the informal reality of open source maintainers has become the operational reality of the entire software world. Companies must adapt quickly to keep up with the requirements of the EU CRA, or risk facing serious consequences.


Source: Bleeping Computer — 2026-09-08