SBOM · Licensing · Vulnerabilities · Supply chain

One CRA reference, two readings: Legal and Cybersecurity

Regulation (EU) 2024/2847 requires a software bill of materials and a vulnerability handling process for every product with digital elements placed on the Union market. This site defines the framework once, then translates it into concrete obligations for each team.

Penalties: up to EUR 15 million or 2.5 % of total worldwide annual turnover — plus a ban on, or withdrawal from, the Union market.

Where to start

The binding timeline

  1. deadline passed

    Notified bodies: the chapter on notification of conformity assessment bodies applies

  2. in 22 days

    Reporting: the Article 14 obligations apply, including to products already on the market

  3. in 478 days

    Full application: CE marking, technical documentation, SBOM and support period

Countdown frozen at the site build date: August 20, 2026.

The three pillars of this reference

All sections