Compliance & Quality

Cyber Resilience Act Component Sourcing: 11 Questions Your Supplier Must Answer

Cyber Resilience Act Component Sourcing: 11 Questions Your Supplier Must Answer

From 11 September 2026, manufacturers selling products with digital elements in the EU must report actively exploited vulnerabilities to their national CSIRT within 24 hours, and a vulnerability sitting inside a bought-in component counts. The Cyber Resilience Act, Regulation (EU) 2024/2847, makes the company whose name is on the CE mark answerable for parts it did not design and did not make. That turns component procurement from a cost exercise into an evidence exercise, and it changes what a purchase order has to capture.

What changes on 11 September 2026

Article 14 reporting obligations apply from 11 September 2026. From that date a manufacturer that becomes aware of an actively exploited vulnerability, or of a severe incident affecting the security of its product, has 24 hours to file an early warning, 72 hours to file a full notification, and 14 days after a corrective measure is available to file the final report. For severe incidents the final report is due within one month. Reports are filed once, through the CRA Single Reporting Platform, to the CSIRT of the member state where the manufacturer has its main establishment, and the information reaches ENISA at the same time. The European Commission reporting guidance sets out the mechanism.

Two points matter for buyers. The clock is 24 hours, not 24 business hours, so nobody has time to email a broker and wait for an answer. And the obligation applies to products already on the EU market, not only to designs released after the date. A board you shipped in 2024 is in scope from day one.

Why component buyers are now inside someone else's compliance file

The CRA defines a product with digital elements as a software or hardware product and its remote data processing solutions, including software or hardware components placed on the market separately. A component sold on its own can therefore be a regulated product in its own right, and a component integrated into your board is something you must exercise due diligence over. The Commission summary of the legislative text puts it plainly: where a manufacturer integrates third-party components, it must exercise due diligence so those components do not compromise the cybersecurity of the finished product.

Due diligence is not a feeling. In an audit it is a paper trail: which part, from which original manufacturer, through which channel, with which lot and date code, and what you did to satisfy yourself the part was genuine and supported. Most European OEM buyers already produce three quarters of that evidence for other reasons. REACH forced substance declarations down the supply chain, RoHS forced material data, and counterfeit avoidance forced lot traceability. The CRA adds a fourth column to the same table rather than a new table.

The gap is usually the channel record. A part bought from a franchised distributor carries an unbroken line back to the manufacturer. A part bought on the open market to keep a line running does not, unless somebody wrote the evidence down at goods-in. That is the record an incident report will expose.

The 11 questions your component supplier must answer

Ask these before the purchase order, not after an incident. Any supplier who cannot answer questions 1 to 5 in writing should not be shipping parts into a CE-marked product.

# Question to the supplier What a good answer looks like
1 Who is the original component manufacturer, stated by name? The brand on the part, not "a major manufacturer" or "an authorised source"
2 What lot code, date code and country of origin ship with this stock? Specific values quoted before order, not "will advise"
3 Through how many hands has this stock passed since the manufacturer? A named chain, or an explicit statement that it is open-market stock
4 Will you issue a Certificate of Conformance naming the manufacturer part number and lot? A sample CoC supplied on request, before the order
5 What incoming inspection or counterfeit testing was performed, to which standard? A test report referencing AS6081 inspection levels or AS6171 methods
6 Does this part carry any published security advisory or errata today? A checked answer with a date, not a shrug
7 Is the part active, NRND, or end of life at the manufacturer? Current lifecycle status, with the source of that status
8 Has a PCN been issued against this part number in the last 24 months? The PCN reference number, or a confirmed no
9 Does the part contain firmware, a boot ROM, or programmable non-volatile memory? A yes or no per part, because a yes pulls it into your update plan
10 Can you supply the same part number again in 12 and 36 months? A stock or allocation position, not a hope
11 Will you notify us if you learn of a vulnerability in a part you sold us? A written commitment in the terms, not a verbal one

Question 9 is the one buyers skip. A passive part cannot carry a vulnerability, but a great deal of what looks passive on a BOM is not. Ethernet PHYs, transceivers, sensor hubs, power management ICs with configuration EEPROM and anything with a serial configuration interface can hold state that an attacker can reach. Splitting the BOM into "can hold code or configuration" and "cannot" takes an afternoon and shrinks the CRA-relevant part count by most of its length.

The Article 2(6) spare-parts carve-out most buyers miss

Spare parts sit outside the Regulation when they replace identical components and are manufactured to the same specifications as the parts they replace, under Article 2(6). This is the single most useful carve-out for anyone maintaining installed equipment in the field, and it is routinely missed because it sits in the scope article rather than in the obligations chapters.

The trap is the word identical. A pin-compatible second source is not identical. A newer die revision of the same part number, shipped after a process change, may not be identical in any characteristic that matters to cybersecurity. If you are buying obsolete parts to support a repair pool, the carve-out holds only while you are genuinely buying the same part built to the same specification. The moment you accept an alternative because the original is gone, you are back inside the Regulation, and the substitution needs to be documented as an engineering change rather than slipped through as like-for-like.

Practical consequence: keep repair-pool purchasing and new-build purchasing on separate approval paths. Buyers who run both through one process end up applying the carve-out to new production, which is exactly the mistake a market surveillance authority will find first.

A worked example: sourcing an Ethernet PHY under CRA due diligence

Take a real line. The Microchip KSZ8081MNXIA-TR, a 10/100 Ethernet PHY, is the kind of part that sits quietly on an industrial controller BOM and never gets a compliance conversation. It is also the part that puts the controller on a network, which is what brings the whole product inside the CRA in the first place.

As of September 2026 the GlobX catalogue page for that part shows 2,000 pieces available, date code 22+, country of origin CN. Those three facts are the start of the due diligence record, and they answer questions 1, 2 and 10 in the table above before anyone picks up a phone. Date code 22+ tells you the stock predates the current production run, which is a question worth asking and answering rather than discovering at goods-in. Country of origin CN tells you which customs and traceability documents will exist. Neither fact is a problem on its own. Both are facts you want written down before the order rather than reconstructed after an incident.

The remaining work is what a distributor should do with you: confirm the lifecycle status at Microchip, check whether a PCN has been issued against the part number, and issue a Certificate of Conformance that names the manufacturer part number and the lot. GlobX quotes with the date code and country of origin visible on the offer and supplies the conformance paperwork with the shipment, which closes the file at the point of purchase instead of six months later. If you need the same evidence trail across a whole BOM rather than one line, send the BOM and ask for it line by line.

The dates that still matter

Chapter IV, covering notified bodies, applied from 11 June 2026. Reporting under Article 14 applies from 11 September 2026. The main obligations, including the essential cybersecurity requirements and conformity assessment, apply from 11 December 2027. That last date is the one that changes designs, and it is close enough that parts being selected now will still be in production when it arrives.

The support period is the design constraint that should be reaching purchasing today. Article 13(8) sets a floor of at least five years, unless the product is expected to be in use for less, and products reasonably expected to last longer should be supported longer. A part that goes not recommended for new designs eighteen months into a ten-year support commitment stops being merely a sourcing problem, because you have promised to keep handling vulnerabilities in a product you may no longer be able to build. Lifecycle status and support period are now the same conversation, and the cheapest time to have it is during part selection. Teams building that discipline from scratch usually start with the channel choices set out in our guide to sourcing electronic components.

If your BOM has lines you cannot currently trace to an original manufacturer, that list is your September action item. Everything else can wait until 2027.

Frequently Asked Questions

Does the Cyber Resilience Act apply to individual electronic components?

Yes. The CRA defines a product with digital elements to include hardware and software components placed on the market separately. A component sold on its own can be a regulated product, and a component you integrate is something you must exercise due diligence over. Purely passive parts holding no code or configuration state are not the target.

Is the Cyber Resilience Act in force yet?

It is in force and applying in stages. Regulation (EU) 2024/2847 entered into force in December 2024. Chapter IV applied from 11 June 2026, Article 14 reporting obligations from 11 September 2026, and the main obligations including conformity assessment apply from 11 December 2027.

Who does the Cyber Resilience Act apply to?

Primarily manufacturers, meaning whoever places the product on the EU market under their own name or trademark. Importers and distributors carry lighter duties: verify the CE marking is present, confirm the manufacturer met its obligations, refrain from making non-compliant products available, and report vulnerabilities they learn about to the manufacturer.

Does a component distributor have obligations under the CRA?

A distributor must check that CE marking is present and that the manufacturer and importer fulfilled their obligations, must not make a non-compliant product available, must inform the manufacturer of vulnerabilities it becomes aware of, and must cooperate with market surveillance authorities. It does not carry the manufacturer reporting duty.

How long is the CRA support period?

At least five years under Article 13(8), unless the product is expected to be in use for less than five years, in which case the support period matches the expected use time. Products reasonably expected to stay in service longer should be supported longer. The end date, month and year, must be stated at the point of purchase.

Do I need a hardware bill of materials, or just an SBOM?

The Regulation requires a software bill of materials covering at least the top-level dependencies. There is no separate hardware BOM mandate, but the due diligence duty on third-party components means you need component-level traceability records anyway. Most teams extend the existing BOM with lifecycle, lot and channel fields rather than building a second document.

Does the CRA apply in the UK?

Not directly. The CRA is EU law and binds products placed on the EU market, so a UK manufacturer selling into the EU is in scope for those products. The UK runs its own regime under the Product Security and Telecommunications Infrastructure Act, which is narrower and covers consumer connectable products.

Does the CRA replace the Radio Equipment Directive cybersecurity rules?

Effectively yes, for products falling in both scopes. The delegated act under the Radio Equipment Directive covering internet-connected radio equipment was deferred so the CRA becomes the single route once its main obligations apply from 11 December 2027. Until then, check which regime your specific product class currently sits under.

Need these parts? GlobX can help

GlobX is an independent distributor for electronic component sourcing in Europe - we locate hard-to-find, obsolete and allocated parts through a verified global network, with ISO 9001 anti-counterfeit inspection, full traceability and 24-hour quotes.

Related posts

AS6081 vs AS6171: Which Counterfeit Test Standard Your Supplier Should Follow
Compliance & Quality

AS6081 vs AS6171: Which Counterfeit Test Standard Your Supplier Should Follow

24 Aug 2026
Moisture Sensitivity Level (MSL) Explained: Floor Life, Dry Pack and Baking
Compliance & Quality

Moisture Sensitivity Level (MSL) Explained: Floor Life, Dry Pack and Baking

12 Aug 2026
Certificate of Conformance for Electronic Components: What It Must Contain
Compliance & Quality

Certificate of Conformance for Electronic Components: What It Must Contain

07 Aug 2026