What changes and when
The EU Cyber Resilience Act (CRA), in force since December 10, 2024, reaches its first major milestone on September 11, 2026: manufacturers must report actively exploited vulnerabilities and incidents to the European Union Agency for Cybersecurity (ENISA). The Act’s main security requirements apply from December 11, 2027, after which non-compliant products cannot be placed on the EU market.
What developers and vendors must do
- Operate a Product Security Incident Response Team (PSIRT) with defined reporting timelines.
- Produce and maintain an SBOM and technical documentation as part of the “definition of done.”
- Plan a conformity route early — it affects schedules, documentation depth, and test evidence.
Open source gets special treatment
The Commission published practical guidance on July 27, 2026, and has updated its guidance on free and open-source software (FOSS). FOSS is generally out of scope unless it is placed on the market in the course of a commercial activity. Penalties for non-compliance can reach €15 million or 2.5% of global annual turnover, whichever is higher.
Source: European Commission Digital Strategy; OpenSSF; devops.com (2026).
