Who the CRA applies to
The CRA (Regulation (EU) 2024/2847) regulates products with digital elements — any software or hardware that connects, directly or indirectly, to a device or network. Its obligations reach further than NIS2 or DORA: they follow the product across the supply chain, not just the operator.
Manufacturers
Bear the core obligations: essential cybersecurity requirements, conformity assessment, CE marking and technical documentation for the entire support period.
Software developers
Must build in secure-by-design and secure-by-default practices, coordinated vulnerability handling, and a software bill of materials (SBOM).
Importers
Must verify that products they place on the EU market carry CE marking, valid conformity assessment and complete documentation.
Distributors
Must act with due diligence, checking conformity and passing vulnerability and incident information along the chain.
Two deadlines that are already close
The CRA entered into force in December 2024 with a phased runway. Two dates matter most — and the first is a reporting obligation with a 24-hour clock attached.
- 11 Sep 2026
Reporting obligations apply
Actively exploited vulnerabilities and severe incidents must be reported to ENISA and your national CSIRT: an early warning within 24 hours, a full notification within 72 hours, and a final report within 14 days.
- 11 Dec 2027
Full application
All essential requirements apply. Products need CE marking, completed conformity assessment, an SBOM, documented vulnerability handling and defined security-update and end-of-life support periods to stay on the EU market.
The obligations that need continuous work
Most CRA duties are not one-off paperwork — they run for the product’s entire support period. That is where security has to be operational, not annual. Here is how River Security’s four services line up with the requirements you have to sustain.
SBOM & CVE tracking
The CRA requires an SBOM and continuous monitoring of the components in your products. Active Focus keeps an accurate, evolving picture of what you expose and which known vulnerabilities affect it — so a new CVE against a dependency surfaces as a tracked issue, not a surprise.
Vulnerability handling
Article 13 demands you identify, document and remediate vulnerabilities throughout the support period. Continuous, expert-led testing proves whether a weakness is actually exploitable and gives your developers prioritized, verified fixes rather than scanner noise.
24 / 72‑hour reporting
Article 14 puts a clock on actively exploited vulnerabilities and severe incidents. Our incident response capability helps you detect, triage and produce the early warning, notification and final report within the CRA’s deadlines.
Conformity & evidence
Conformity assessment and technical documentation depend on being able to show what was tested, what was found, and how it was fixed. Active Focus keeps that history continuously — a running, audit-ready record of your security posture that maps to the CRA’s essential requirements for assessors and technical files.

One continuous engine for CRA vulnerability handling
The hardest parts of the CRA — knowing your components, catching new CVEs against them, proving remediation, and reporting exploitation on time — all describe continuous work, not an annual audit. Active Focus combines attack surface management and expert penetration testing into a single always-on service, with the platform holding the history of what was found, when, and how it was fixed. That record is exactly the evidence CRA conformity and incident reporting depend on.
From our customers
View all testimonialsPreparing for the CRA?
Book a short call and we will walk you through where you stand against the CRA’s vulnerability handling, SBOM and reporting obligations — and how to close the gaps before the deadlines.
Schedule a CRA readiness callCompliance and regulation content from our team

Guide to Navigate the Most Common Frameworks and Regulations for Cyber Security
In this comprehensive guide I will go through the most common frameworks and regulations for Cyber Security, as there might be some confusion in how t…

SSL/TLS Management: Reducing Risks and Gaining Visibility
Transport Layer Security (TLS) and its predecessor SSL remain cornerstones of modern internet security. They protect confidentiality, integrity, and a…

Continuous Security, Real Risk Insights, and Business Value – Why Our Customers Choose Active Focus
A few years back, River Security developed and launched Active Focus, a world-first, disruptive IT security technology and service enabling penetratio…






