Europe's Software Supply Chain Gets a Deadline: What the Cyber Resilience Act Means for Manufacturers and Their Suppliers
Published on 10/06/2026 at 08:50 | Editorial boerse-global.de
A single date now anchors much of the planning chatter in European manufacturing: 11 December 2027. That is when the Cyber Resilience Act (CRA) makes a Software Bill of Materials (SBOM) mandatory for makers of products with digital elements. The requirement is not going away, and it is already reshaping how companies think about everything they build, buy, or embed.
The SBOM Rule and What It Actually Demands
Under the CRA, manufacturers must produce an SBOM — a structured inventory of the software components inside a product. Publishing it openly is not required. Market surveillance authorities, however, can demand to see the documents when they need to.
The SBOM is one piece of a broader compliance picture. Before a product can carry the CE mark, its maker has to demonstrate that required security standards are met. That includes secure factory settings and procedures for detecting vulnerabilities, alongside the software inventory itself.
Germany's BSI TR-03183 guideline offers a template for how SBOMs should be formatted. It is explicitly a non-binding orientation aid. It does not create a legal presumption of conformity under the European framework — a distinction that matters for anyone treating it as a compliance shortcut.
Suppliers Feel the Pressure Indirectly
Companies that do not make their own end products are not off the hook. The regulatory wave reaches them through contracts. Clients chasing their own compliance obligations now demand detailed information about supplied modules, pushing SBOM expectations down the value chain.
For businesses in scope, the practical starting point is a full inventory of devices and software. From there, the work involves identifying in-house developments and requesting structured component lists from external service providers.
Industry observers stress that CRA readiness is not a one-off audit. It has to be embedded as an ongoing process spanning the entire product lifecycle.
Pilot projects on connected products — the Yale Linus L2 smart lock and systems from manufacturer tado°, for instance — illustrate where the focus lands in practice: protocol testing, authentication, risk assessments, and documentation of security procedures.
Reporting Duties Are Already Live
Not everything waits for December 2027. Since 11 September 2026, manufacturers and open-source software stewards have been subject to strict reporting obligations for actively exploited vulnerabilities. The same date marked the launch of the Single Reporting Platform (SRP) run by ENISA, the EU's cybersecurity agency.
Article 14 of the regulation sets out a tight clock. An early warning is due within 24 hours of an actively exploited vulnerability or severe incident. A detailed main notification follows within 72 hours, and a final report is required after 14 days.
These rules apply to products already on the European market, too. That leaves companies tracking security gaps not only in new developments but also in legacy systems and open-source components — indefinitely.
