From 11 September 2026, manufacturers selling products with digital elements in the EU must report actively exploited vulnerabilities to their national CSIRT within 24 hours, and a vulnerability sitting inside a bought-in component counts. The Cyber Resilience Act, Regulation (EU) 2024/2847, makes the company whose name is on the CE mark answerable for parts it did not design and did not make. That turns component procurement from a cost exercise into an evidence exercise, and it changes what a purchase order has to capture.
What changes on 11 September 2026
Article 14 reporting obligations apply from 11 September 2026. From that date a manufacturer that becomes aware of an actively exploited vulnerability, or of a severe incident affecting the security of its product, has 24 hours to file an early warning, 72 hours to file a full notification, and 14 days after a corrective measure is available to file the final report. For severe incidents the final report is due within one month. Reports are filed once, through the CRA Single Reporting Platform, to the CSIRT of the member state where the manufacturer has its main establishment, and the information reaches ENISA at the same time. The European Commission reporting guidance sets out the mechanism.
Two points matter for buyers. The clock is 24 hours, not 24 business hours, so nobody has time to email a broker and wait for an answer. And the obligation applies to products already on the EU market, not only to designs released after the date. A board you shipped in 2024 is in scope from day one.
Why component buyers are now inside someone else's compliance file
The CRA defines a product with digital elements as a software or hardware product and its remote data processing solutions, including software or hardware components placed on the market separately. A component sold on its own can therefore be a regulated product in its own right, and a component integrated into your board is something you must exercise due diligence over. The Commission summary of the legislative text puts it plainly: where a manufacturer integrates third-party components, it must exercise due diligence so those components do not compromise the cybersecurity of the finished product.
Due diligence is not a feeling. In an audit it is a paper trail: which part, from which original manufacturer, through which channel, with which lot and date code, and what you did to satisfy yourself the part was genuine and supported. Most European OEM buyers already produce three quarters of that evidence for other reasons. REACH forced substance declarations down the supply chain, RoHS forced material data, and counterfeit avoidance forced lot traceability. The CRA adds a fourth column to the same table rather than a new table.
The gap is usually the channel record. A part bought from a franchised distributor carries an unbroken line back to the manufacturer. A part bought on the open market to keep a line running does not, unless somebody wrote the evidence down at goods-in. That is the record an incident report will expose.
The 11 questions your component supplier must answer
Ask these before the purchase order, not after an incident. Any supplier who cannot answer questions 1 to 5 in writing should not be shipping parts into a CE-marked product.
| # | Question to the supplier | What a good answer looks like |
|---|---|---|
| 1 | Who is the original component manufacturer, stated by name? | The brand on the part, not "a major manufacturer" or "an authorised source" |
| 2 | What lot code, date code and country of origin ship with this stock? | Specific values quoted before order, not "will advise" |
| 3 | Through how many hands has this stock passed since the manufacturer? | A named chain, or an explicit statement that it is open-market stock |
| 4 | Will you issue a Certificate of Conformance naming the manufacturer part number and lot? | A sample CoC supplied on request, before the order |
| 5 | What incoming inspection or counterfeit testing was performed, to which standard? | A test report referencing AS6081 inspection levels or AS6171 methods |
| 6 | Does this part carry any published security advisory or errata today? | A checked answer with a date, not a shrug |
| 7 | Is the part active, NRND, or end of life at the manufacturer? | Current lifecycle status, with the source of that status |
| 8 | Has a PCN been issued against this part number in the last 24 months? | The PCN reference number, or a confirmed no |
| 9 | Does the part contain firmware, a boot ROM, or programmable non-volatile memory? | A yes or no per part, because a yes pulls it into your update plan |
| 10 | Can you supply the same part number again in 12 and 36 months? | A stock or allocation position, not a hope |
| 11 | Will you notify us if you learn of a vulnerability in a part you sold us? | A written commitment in the terms, not a verbal one |
Question 9 is the one buyers skip. A passive part cannot carry a vulnerability, but a great deal of what looks passive on a BOM is not. Ethernet PHYs, transceivers, sensor hubs, power management ICs with configuration EEPROM and anything with a serial configuration interface can hold state that an attacker can reach. Splitting the BOM into "can hold code or configuration" and "cannot" takes an afternoon and shrinks the CRA-relevant part count by most of its length.
The Article 2(6) spare-parts carve-out most buyers miss
Spare parts sit outside the Regulation when they replace identical components and are manufactured to the same specifications as the parts they replace, under Article 2(6). This is the single most useful carve-out for anyone maintaining installed equipment in the field, and it is routinely missed because it sits in the scope article rather than in the obligations chapters.
The trap is the word identical. A pin-compatible second source is not identical. A newer die revision of the same part number, shipped after a process change, may not be identical in any characteristic that matters to cybersecurity. If you are buying obsolete parts to support a repair pool, the carve-out holds only while you are genuinely buying the same part built to the same specification. The moment you accept an alternative because the original is gone, you are back inside the Regulation, and the substitution needs to be documented as an engineering change rather than slipped through as like-for-like.
Practical consequence: keep repair-pool purchasing and new-build purchasing on separate approval paths. Buyers who run both through one process end up applying the carve-out to new production, which is exactly the mistake a market surveillance authority will find first.
A worked example: sourcing an Ethernet PHY under CRA due diligence
Take a real line. The Microchip KSZ8081MNXIA-TR, a 10/100 Ethernet PHY, is the kind of part that sits quietly on an industrial controller BOM and never gets a compliance conversation. It is also the part that puts the controller on a network, which is what brings the whole product inside the CRA in the first place.
As of September 2026 the GlobX catalogue page for that part shows 2,000 pieces available, date code 22+, country of origin CN. Those three facts are the start of the due diligence record, and they answer questions 1, 2 and 10 in the table above before anyone picks up a phone. Date code 22+ tells you the stock predates the current production run, which is a question worth asking and answering rather than discovering at goods-in. Country of origin CN tells you which customs and traceability documents will exist. Neither fact is a problem on its own. Both are facts you want written down before the order rather than reconstructed after an incident.
The remaining work is what a distributor should do with you: confirm the lifecycle status at Microchip, check whether a PCN has been issued against the part number, and issue a Certificate of Conformance that names the manufacturer part number and the lot. GlobX quotes with the date code and country of origin visible on the offer and supplies the conformance paperwork with the shipment, which closes the file at the point of purchase instead of six months later. If you need the same evidence trail across a whole BOM rather than one line, send the BOM and ask for it line by line.
The dates that still matter
Chapter IV, covering notified bodies, applied from 11 June 2026. Reporting under Article 14 applies from 11 September 2026. The main obligations, including the essential cybersecurity requirements and conformity assessment, apply from 11 December 2027. That last date is the one that changes designs, and it is close enough that parts being selected now will still be in production when it arrives.
The support period is the design constraint that should be reaching purchasing today. Article 13(8) sets a floor of at least five years, unless the product is expected to be in use for less, and products reasonably expected to last longer should be supported longer. A part that goes not recommended for new designs eighteen months into a ten-year support commitment stops being merely a sourcing problem, because you have promised to keep handling vulnerabilities in a product you may no longer be able to build. Lifecycle status and support period are now the same conversation, and the cheapest time to have it is during part selection. Teams building that discipline from scratch usually start with the channel choices set out in our guide to sourcing electronic components.
If your BOM has lines you cannot currently trace to an original manufacturer, that list is your September action item. Everything else can wait until 2027.