TL;DRStarting September 11, the EU Cyber Resilience Act will require manufacturers to notify regulators within 24 hours of learning a vulnerability in their product is being actively exploited. For companies whose products contain software from multiple suppliers, the bottleneck is not having an SBOM but knowing whether it accurately reflects the underlying code. FossID’s Aaron Branson argues source-code analysis provides the verification layer that turns SBOM documents into reliable supply-chain intelligence.
According to an analysis published by The Hacker News, manufacturers of products with digital elements sold in the European Union will face a September 11 deadline under the Cyber Resilience Act (CRA) to notify regulators within 24 hours after learning that a vulnerability is being actively exploited, with a fuller report due within 72 hours. For manufacturing executives, the 24-hour window may bring greater attention to software supply-chain visibility. Complex products can contain proprietary software, supplier-developed applications, commercial packages, microcontroller software, and open-source libraries, with dependencies extending across several tiers. A manufacturer may maintain numerous supplier relationships while having limited insight into the software embedded within individual components.









