SBOMClock

EU Cyber Resilience Act · Article 14

Your 24-hour clock starts 11 September 2026.

If you place software on the EU market, you are now required to report actively exploited vulnerabilities to ENISA within 24 hours of becoming aware of them — including in products you shipped years ago.

REPORTING OBLIGATION LIVE 2026-09-11 · penalties to €15M or 2.5% of global turnover

The hard part isn't the report. It's knowing you owe one.

The 24-hour window starts when you become aware. That means someone has to be watching every dependency in every product you ship, continuously, against the vulnerabilities that are actually being exploited in the wild — not the 40,000 CVEs published each year, but the roughly 1,700 on CISA's Known Exploited Vulnerabilities catalogue and its equivalents.

Most small vendors have no such process. Linux Foundation research found only 32% of manufacturers produce an SBOM for all products, and 41% have not yet determined whether the CRA applies to them at all.

Who
Manufacturers placing products with digital elements on the EU market. Importers and distributors carry related duties.
What
Early warning to ENISA within 24 hours of awareness of an actively exploited vulnerability; fuller notification within 72 hours.
From
11 Sep 2026 — reporting duties. Full obligations, including SBOM in technical documentation, from 11 Dec 2027.
Exposure
Up to €15 million or 2.5% of worldwide annual turnover, plus market restrictions and recalls.

What this does

  1. You send us a lockfile Your package-lock.json or requirements.txt — whatever your product actually ships with. No source code, no repo access.
  2. We generate the component inventory and check it Every component is matched against the CISA Known Exploited Vulnerabilities catalogue — the roughly 1,700 vulnerabilities confirmed under active exploitation, not the 40,000-plus CVEs published each year. This is the automated, working part: the same matching engine, re-run against the current catalogue.
  3. You get told before the clock runs out If a component you ship appears on the exploited list, you get the affected product, the version, and a pre-filled draft of the ENISA Article 14 early warning — ready for your review, not auto-submitted anywhere.

Founding member pricing

$79per month, all products

Flat rate. No per-seat, per-repository or per-scan pricing. Existing compliance platforms start around $250–800/month and are built for teams with a dedicated security function.

Start monitoring

Cancel anytime. No contract.

Subscribe — $79/month
  1. Subscribe above.
  2. Email your package-lock.json or requirements.txt to intake@sbomclock.com.
  3. Get your first report within 24 hours.
Being straight with you, since this is a real charge: the SBOM-generation and KEV-matching engine is built and tested — it's not vaporware behind a payment button. What's manual right now, as a founding member, is onboarding: there's no automatic GitHub connection yet, so you send us the lockfile directly, and again whenever your dependencies change materially. We re-run your check against the current KEV catalogue every few days. Automatic repo connection and continuous real-time monitoring are the next things we build, and founding members get moved onto that automatically at no extra cost when it ships.