Cyber Resilience Act: monitor your components and your exposure
The EU's Cyber Resilience Act requires manufacturers of digital products to manage vulnerabilities throughout the product lifecycle — with, from September 2026, the obligation to report actively exploited vulnerabilities within 24 hours. Knowing immediately which of your exposed components are affected is no longer a comfort: it is a deadline.
The CRA at a glance
What the Cyber Resilience Act changes,
in three points
- Every digital product sold in the EU Regulation (EU) 2024/2847, in force since December 2024, applies to manufacturers of products with digital elements: software, connected devices, equipment — European or not, as long as they sell in the Union. CE marking will embed these requirements.
- Vulnerability management becomes a legal obligation Manufacturers must identify and document vulnerabilities in their products and components, provide security updates during the support period, and organize coordinated disclosure.
- A calendar that starts in September 2026 Reporting obligations apply from September 2026: any actively exploited vulnerability must be reported within 24 hours (early warning), ahead of general application at the end of 2027. Penalties: up to €15M or 2.5% of worldwide turnover.
Where Purplemet fits
Two CRA requirements rest on a capability we provide
No tool "makes you CRA compliant" — compliance runs through secure design, technical documentation, CE marking and internal processes. Two requirements, however, rest on a capability Purplemet provides: knowing continuously which components run where, and being alerted immediately when one becomes dangerous.
- Continuous component watch The CRA expects manufacturers to know and track the components of their products and the vulnerabilities affecting them. For everything exposed on the web — your SaaS products, customer portals, APIs, update services, demo environments — Purplemet inventories the technology stack (components, versions) and continuously matches it against published CVEs.
- Meeting the 24-hour deadline Reporting an actively exploited vulnerability within 24 hours presupposes knowing, without delay, whether it concerns you. Purplemet crosses actively exploited vulnerabilities with your exposed inventory: when an alert drops, you know immediately whether one of your components is affected — which one, and where.
- The manufacturer's own attack surface Attacks against software vendors often come through their own exposed infrastructure: download portal, update server, customer area. Purplemet discovers and monitors your entire web exposure — including forgotten assets that would make you the weak link of your own supply chain.
- Documenting diligence In the event of an audit or an incident, demonstrating continuous monitoring of your exposed components and their vulnerabilities objectifies your diligence — Purplemet's history is the record.
Common questions about the CRA and Web ASM
Does Purplemet make me CRA compliant?
No — no tool can. CRA compliance runs through secure product design, technical documentation, conformity assessment and CE marking. Purplemet answers a specific operational need the regulation creates: continuous monitoring of exposed components and their vulnerabilities, notably to meet reporting deadlines.
Who is in scope of the CRA, and from when?
Any manufacturer — European or not — of products with digital elements sold in the EU: software, connected devices, equipment. The regulation has been in force since December 2024; reporting obligations for actively exploited vulnerabilities apply from September 2026, and most obligations from the end of 2027.
What must be reported within 24 hours under the CRA?
Any actively exploited vulnerability affecting a covered product, as well as severe incidents affecting its security: an early warning within 24 hours, followed by detailed information within the deadlines set by the regulation. Meeting that deadline presupposes knowing immediately whether a published vulnerability concerns your components — hence the importance of an exposed inventory kept continuously up to date.

