From 11 September 2026, you have 24 hours.
The EU Cyber Resilience Act makes vulnerability reporting a legal duty — an early warning within 24 hours for actively exploited vulnerabilities, including in products you’ve already shipped. OSPulse tells you what’s in your products, watches for active exploitation, and has your report pack ready before the clock hurts.
begin · 11 September 2026
Early warning within 24 hours — the law from 11 September 2026
Fines up to €15M or 2.5% of worldwide annual turnover
Applies to products already on the EU market
One scan → SBOM + exploit watch + report packs
Know what you’d have to report — before you have to report it.
The Cyber Resilience Act doesn’t ask you to report every CVE. It asks for something harder: to know, within 24 hours, that a component in one of your shipped products is being actively exploited — and to notify ENISA’s Single Reporting Platform with an early warning in 24 hours and a full notification in 72.
That’s three capabilities most small software teams don’t have:
A live inventory of what’s actually in your products.
OSPulse generates a CycloneDX SBOM for every product release from the scans you’re already running. Legacy product with no pipeline? Upload once — the CRA covers software you shipped years ago, and so do we.
An exploit watch, not a CVE firehose.
The reporting trigger is active exploitation. OSPulse maps every component against exploitation intelligence — CISA KEV, in-the-wild exploit signals, and our own supply-chain compromise detection — and separates Reportable from Track. You act on the four findings that matter, not the four hundred that don’t.
Clocks and reports that hold up.
The moment a Reportable finding fires, OSPulse starts the legal clocks: 24-hour early warning, 72-hour notification, and a final report within 14 days of a corrective measure (one month for a severe incident). Every stage exports a submission-ready pack aligned to the Single Reporting Platform’s fields, with a full evidential audit trail from awareness to closure. Your lawyer signs; you don’t scramble.
And when December 2027 arrives, you’re already there.
Reporting is only the CRA’s first act. Full application lands 11 December 2027: essential security requirements, technical documentation, CE marking. OSPulse’s Annex I readiness checklist tracks every requirement against linked evidence — so compliance is a byproduct of how you already ship, not a six-month archaeology project.
Built into your pipeline, not bolted onto your calendar.
Add a cra: block to your OSPulse CI policy and releases gate themselves: no SBOM, no ship; an unacknowledged Reportable finding, no ship — with baselines and expiring exceptions so day one doesn’t break every build.
Frequently asked
Does OSPulse make us CRA compliant?
No tool can. OSPulse gives you the inventory, monitoring, deadlines, and submission-ready evidence the CRA’s reporting duties demand — your team (and, for many firms, your counsel) makes the compliance decisions. We make those decisions fast and defensible instead of panicked.
We’re a UK company — does the CRA apply to us?
If you place products with digital elements on the EU market, yes, regardless of where you’re based.
Do we have to report every vulnerability?
No. The Article 14 duty covers actively exploited vulnerabilities and severe incidents affecting product security. That distinction is exactly what OSPulse’s classification engine is for.
We shipped our product years ago and barely touch it. Are we in scope?
If it’s still on the EU market, the reporting duties apply from 11 September 2026. OSPulse supports manual SBOM upload for products without an active pipeline.
Does OSPulse submit reports to ENISA for us?
Today we export submission-ready packs for every reporting stage. Direct platform submission is on the roadmap, pending ENISA’s platform capabilities.
While you’re in there: the same scan that answers the CRA answers the next deadline too. NIST deprecates RSA and ECC around 2030 — OSPulse’s Quantum Proofing Scanner already knows where yours are.
Get ahead of the clock.
Evidence and speed when a Reportable finding fires — not a scramble. OSPulse is in early access now.
