The 24-hour CRA deadline is changing software supply chain visibility

https://media.thenextweb.com/2026/09/cra-24-hour-deadline-software-supply-chain-sbom.jpg

TL;DR

Starting September 11, the EU Cyber Resilience Act will require manufacturers to notify regulators within 24 hours of learning a vulnerability in their product is being actively exploited. For companies whose products contain software from multiple suppliers, the bottleneck is not having an SBOM but knowing whether it accurately reflects the underlying code. FossID’s Aaron Branson argues source-code analysis provides the verification layer that turns SBOM documents into reliable supply-chain intelligence.

According to an analysis published by The Hacker News, manufacturersof products with digital elements sold in the European Union will face a September 11 deadline under the Cyber Resilience Act (CRA) to notify regulators within 24 hours after learning that a vulnerability is being actively exploited, with a fuller report due within 72 hours. For manufacturing executives, the 24-hour window may bring greater attention to software supply-chain visibility. Complex products can contain proprietary software, supplier-developed applications,...

Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE