Overview
- Reporting obligations for actively exploited vulnerabilities and severe incidents became effective on Sept. 11, 2026 and require an early warning within 24 hours and a fuller notification within 72 hours through ENISA’s Single Reporting Platform.
- The CRA’s scope explicitly covers container images, Kubernetes operators and Helm charts that have commercial support or are required for a product’s function, which means many cloud‑native components sold to EU customers fall under the law.
- Teams must adopt concrete operational changes such as hardened base images, continuous SBOM and runtime BOM generation, automated rebuild pipelines for older images, and tools to track which container versions are deployed to customers.
- Full conformity assessments and CE marking are not yet enforced until Dec. 11, 2027 but manufacturers are urged to start conformity workflows now because the assessment process and long‑term update duties typically need substantial lead time.
- SMEs and open‑source stewards get tailored support and simplified documentation options, but non‑compliance can block market access and lead vendors to rethink pricing, support windows and product lifecycles to meet required five‑plus year security update duties.