Since 11 September 2026, Article 14 of the Cyber Resilience Act (CRA) has been in effect. Any manufacturer of a product with digital elements sold in the European Union — including ERP vendors — must now notify ENISA of any actively exploited vulnerability within 24 hours via the Single Reporting Platform (SRP). The ENISA SRP has been operational since that date. Penalties can reach €15 million or 2.5% of global annual turnover.
Context: a long-announced obligation that is now operational
Regulation (EU) 2024/2847 entered into force on 11 December 2024. It applies in three stages:
| Date | Obligation |
|---|---|
| 11 June 2026 | Establishment of conformity assessment bodies by Member States |
| 11 September 2026 | Vulnerability and incident reporting obligations (Art. 14) |
| 11 December 2027 | Full compliance: security by design, documentation, CE marking |
The first milestone is now passed. What was a timeline on paper has become an operational legal constraint: an ERP vendor without formal vulnerability detection and reporting processes is today in breach of EU law.
The CRA differs from NIS2, which targets operators of essential services on the buyer side. The CRA targets manufacturers of digital products on the supply side. For ERP vendors, this is no longer a matter of bilateral contractual arrangements with their customers — it is a public regulatory obligation, verifiable by national market surveillance authorities.
What this means in practice for CIOs and CFOs
Notification timelines are strict. Once a vendor identifies an actively exploited vulnerability in its ERP, it must (source: European Commission):
- Submit an early warning within 24 hours via the ENISA SRP
- Deliver a full notification with technical details within 72 hours
- Submit a final report within 14 days after the patch is available, including root cause analysis
- File a closure report for major incidents within one month of the 72-hour notification
For a CIO on the buyer side, this creates an implicit right to timely information: if your vendor discovers a flaw on Monday morning, it must have submitted its early warning to ENISA before Tuesday morning. National CSIRTs — such as the BSI in Germany, NCSC in the Netherlands, or ANSSI in France — then receive this information and can share it at their discretion. The practice of disclosing a critical vulnerability six weeks after discovery, buried in a quiet patch tuesday bulletin, is no longer tenable.
SBOM becomes an operational requirement. To meet these notification deadlines, vendors must maintain a Software Bill of Materials (SBOM) — a structured inventory of all their software components (open-source libraries, dependencies, frameworks). Without an SBOM, it is impossible to know whether a newly published CVE affects their product. Vendors that have not yet industrialised this practice are now in structural non-compliance.
For SMEs running a cloud ERP from a non-European vendor distributed by a local reseller, the situation warrants attention: that reseller qualifies as an “importer” under the CRA and carries its own compliance verification obligations. This is an additional argument for contractually requiring a CRA compliance attestation during the next contract renegotiation.
What to watch between now and end of 2027
Two developments to monitor over the coming months:
The first is the emergence of initial enforcement actions by national CSIRTs. Germany (BSI), the Netherlands (NCSC) and France (ANSSI) are likely to be among the first to process cases. A first documented case will set European precedent on the actual level of scrutiny expected.
The second is the integration of SBOM requirements into ERP procurement. CIOs renewing or launching an ERP project in 2026–2027 now have a regulatory lever to demand SBOM delivery and contractual commitments on CRA notification timelines. This point should appear systematically in every ERP specification document ahead of full compliance in December 2027.
To go further, see our complete guide to the Cyber Resilience Act and ERP systems, our NIS2 compliance guide for mid-market companies using ERP, and our Zero Trust architecture applied to ERP access security.