Standards

Cyber Resilience Act software requirements.

The EU Cyber Resilience Act requires makers of products with digital elements to report actively exploited vulnerabilities from 11 September 2026, and to meet its full security requirements, including a software bill of materials and CE marking, from 11 December 2027.

Last updated .

What applies now

Since 11 September 2026, the duty to report actively exploited vulnerabilities applies to makers of products with digital elements. That means knowing quickly what is in your software and who changed it.

What applies from December 2027

From 11 December 2027 the full security requirements apply, including a software bill of materials and CE marking. Plan for them now, because evidence is easiest to keep as software is built.

DateWhat applies
11 September 2026Makers of products with digital elements must report actively exploited vulnerabilities.
11 December 2027The full security requirements apply, including a software bill of materials and CE marking.

What evidence you will need

Expect to show what your software contains and how it was developed securely. That means a software bill of materials, and records of who approved each change and what was checked before it shipped.

How EmberNest helps you evidence it

Live today: two approvals with segregation of duties on every piece of work, and evidence linked to every change. That is the change and approval record an assessor asks for.

Roadmap: exportable evidence packs. We will describe them as live once they ship. EmberNest helps you evidence compliance. It does not make you compliant or certified.

Get your free assurance report

This page is not legal advice. Dates as given in our plan of 10 October 2026.

All standards

Talk through the Cyber Resilience Act with us.

Book a conversation