Regulation readiness

The Cyber Resilience Act makes secure software the law

From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities to ENISA. From 11 December 2027, the full CRA applies. River Security helps you build the continuous vulnerability handling, SBOM and reporting capability the regulation demands — and prove it.

Who the CRA applies to

The CRA (Regulation (EU) 2024/2847) regulates products with digital elements — any software or hardware that connects, directly or indirectly, to a device or network. Its obligations reach further than NIS2 or DORA: they follow the product across the supply chain, not just the operator.

Manufacturers

Bear the core obligations: essential cybersecurity requirements, conformity assessment, CE marking and technical documentation for the entire support period.

Software developers

Must build in secure-by-design and secure-by-default practices, coordinated vulnerability handling, and a software bill of materials (SBOM).

Importers

Must verify that products they place on the EU market carry CE marking, valid conformity assessment and complete documentation.

Distributors

Must act with due diligence, checking conformity and passing vulnerability and incident information along the chain.

Two deadlines that are already close

The CRA entered into force in December 2024 with a phased runway. Two dates matter most — and the first is a reporting obligation with a 24-hour clock attached.

  1. 11 Sep 2026

    Reporting obligations apply

    Actively exploited vulnerabilities and severe incidents must be reported to ENISA and your national CSIRT: an early warning within 24 hours, a full notification within 72 hours, and a final report within 14 days.

  2. 11 Dec 2027

    Full application

    All essential requirements apply. Products need CE marking, completed conformity assessment, an SBOM, documented vulnerability handling and defined security-update and end-of-life support periods to stay on the EU market.

The obligations that need continuous work

Most CRA duties are not one-off paperwork — they run for the product’s entire support period. That is where security has to be operational, not annual. Here is how River Security’s four services line up with the requirements you have to sustain.

Active Focus

SBOM & CVE tracking

The CRA requires an SBOM and continuous monitoring of the components in your products. Active Focus keeps an accurate, evolving picture of what you expose and which known vulnerabilities affect it — so a new CVE against a dependency surfaces as a tracked issue, not a surprise.

Active Focus

Vulnerability handling

Article 13 demands you identify, document and remediate vulnerabilities throughout the support period. Continuous, expert-led testing proves whether a weakness is actually exploitable and gives your developers prioritized, verified fixes rather than scanner noise.

Incident Response

24 / 72‑hour reporting

Article 14 puts a clock on actively exploited vulnerabilities and severe incidents. Our incident response capability helps you detect, triage and produce the early warning, notification and final report within the CRA’s deadlines.

Active Focus

Conformity & evidence

Conformity assessment and technical documentation depend on being able to show what was tested, what was found, and how it was fixed. Active Focus keeps that history continuously — a running, audit-ready record of your security posture that maps to the CRA’s essential requirements for assessors and technical files.

Active Focus platform tracking vulnerabilities against product components

One continuous engine for CRA vulnerability handling

The hardest parts of the CRA — knowing your components, catching new CVEs against them, proving remediation, and reporting exploitation on time — all describe continuous work, not an annual audit. Active Focus combines attack surface management and expert penetration testing into a single always-on service, with the platform holding the history of what was found, when, and how it was fixed. That record is exactly the evidence CRA conformity and incident reporting depend on.

More about Active Focus

From our customers

At the core of our comprehensive cyber-security approach is the concept of layered protection, ensuring that we are always at the forefront of the latest and greatest innovations in the industry. That’s where River Security comes in, offering their Active Focus service to keep us ahead of the curve with a constantly evolving attack surface, and even helping us to uncover the unknown. With a dynamic blend of cutting-edge technology and skilled expert verification, paired with lightning-fast agility, we are better equipped to tackle any threat that comes our way.

Arvid Eriksen
Arvid EriksenCISO · Sparebanken NorgeFinance
Read more

River Security conducted penetration testing for us, including assessments of our OpenID Connect (OIDC)-based authentication, APIs, integrations, and login/logout flows. The team combines deep technical expertise with an innovative and practical approach to security testing and remediation.

We also tested their Active Focus service, which provides valuable insight into our external attack surface. River Security stands out as highly competent professionals who communicate findings clearly and focus on what truly matters. We are very pleased with the collaboration and are happy to recommend them.

Roger Bløtekjær
Roger BløtekjærCISO · Norsk RikstotoGaming
Read more

Working with River Security gives us an external validation of the security work we’ve invested in over time. Their continuous testing and detailed feedback make it clear where we are doing well and where we need to improve. It’s both reassuring and highly actionable.

Terje Engebretsen
Terje EngebretsenIT Manager · Sea1 OffshoreShipping
Read more
View all testimonials

Preparing for the CRA?

Book a short call and we will walk you through where you stand against the CRA’s vulnerability handling, SBOM and reporting obligations — and how to close the gaps before the deadlines.

Schedule a CRA readiness call

Compliance and regulation content from our team