How UK CISOs Should Prepare for the EU's New SBOM Deadline | INFORMD Executive Briefing

How UK CISOs Should Prepare for the EU’s New SBOM Deadline

The EU Cyber Resilience Act requires UK software vendors selling into Europe to report exploited vulnerabilities to ENISA within 24 hours from 11 September 2026.

That single date changes the calculus for every UK CISO whose products, components, or embedded software touch the EU market. Reporting cannot happen without an accurate inventory of what is actually running in production — which is precisely what a Software Bill of Materials (SBOM) provides. The UK has no equivalent legal mandate yet, but the compliance clock attached to the Cyber Resilience Act (CRA) does not wait for Westminster to catch up.

What is the EU Cyber Resilience Act’s SBOM deadline?

From 11 September 2026, manufacturers of “products with digital elements” sold into the EU — software, IoT devices, industrial control systems, networking equipment — must report actively exploited vulnerabilities to ENISA and national CSIRTs within 24 hours of becoming aware of them. This obligation applies even to legacy products shipped years ago, provided they remain on the market. The formal requirement to maintain and disclose a full SBOM does not become enforceable until December 2027, but the two obligations are inseparable in practice: an organisation cannot report on components it has never inventoried.

The technical baseline behind this is evolving too. According to CISA, the 2026 Minimum Elements for a Software Bill of Materials — published on 29 July 2026 by a coalition including the UK’s NCSC, Germany’s BSI, France’s ANSSI, Canada’s CSE and Japan’s NCO — is the first full revision of the original SBOM baseline, reflecting years of implementation experience across critical sectors.

Executive Action:

  • Confirm with legal counsel whether any product line, embedded firmware, or SaaS offering falls within the CRA’s “digital elements” scope
  • Identify the CISO or delegate accountable for 24-hour vulnerability reporting from 11 September 2026
  • Request a copy of INFORMD’s technology strategy review template at /templates/ to structure the readiness assessment

Does this apply if we don’t sell directly into the EU?

Yes, indirectly, for most mid-sized and large UK organisations. Few software estates are wholly domestic: components get resold through EU distributors, embedded in products manufactured on the continent, or bundled into platforms with European customers. The CRA’s reporting duty sits with the manufacturer placing the product on the EU market, but UK suppliers further up the chain are increasingly asked to produce SBOMs as a condition of contract, well ahead of any formal UK requirement.

Domestically, the position remains voluntary. The UK’s Software Security Code of Practice, overseen by the Department for Science, Innovation and Technology, encourages SBOM adoption as good practice rather than mandating it, and the NCSC’s public backing of the July 2026 international minimum-elements update signals where domestic policy is heading, not where it currently stands. CISOs who treat that gap as breathing room typically discover the gap is smaller than it looks once a single EU-facing customer or reseller asks for evidence.

Executive Action:

  • Map every product, platform, and integration with EU distribution, resale, or customer exposure
  • Ask procurement whether any current EU customer contracts already reference SBOM or CRA compliance clauses
  • Brief the board that voluntary UK guidance is unlikely to remain the end state, using INFORMD’s AI governance and risk self-assessment at /tools-assessments/ as a starting reference

What should CISOs do before 11 September 2026?

Readiness is a data problem before it is a policy problem. According to ENISA’s 2026 SBOM Adoption State of Play survey, 78% of organisations have begun adopting SBOM practices, but only 9% report a fully mature, highly automated implementation — and more than 60% cite achieving comprehensive coverage as their biggest obstacle. The gap between “started” and “operational” is where most reporting failures will occur next month.

Practical priorities in the weeks before the deadline: generate SBOMs in a standard machine-readable format (CycloneDX or SPDX) for anything with EU exposure; establish a vulnerability triage workflow that can move from detection to ENISA notification inside 24 hours, not the multi-day cycle most incident response processes assume; and confirm which team — security engineering, not just compliance — owns the inventory going forward, since SBOMs decay quickly without a maintenance owner.

Executive Action:

  • Pilot SBOM generation on the highest-risk, EU-facing product first rather than attempting full estate coverage before the deadline
  • Test the 24-hour reporting workflow end-to-end, including out-of-hours escalation, before 11 September
  • Assign permanent inventory ownership to security engineering rather than leaving it as a one-off compliance exercise

How does SBOM readiness fit into wider cyber resilience?

SBOM work should not run as an isolated compliance project. It is the software-layer counterpart to the vendor and third-party risk registers many CISOs already maintain for critical suppliers — the same discipline of “know what you depend on and how it fails” applied one layer deeper, to the code itself rather than just the vendor relationship. Organisations that already run mature third-party risk programmes tend to find SBOM adoption faster, because the governance habits — ownership, review cadence, escalation paths — transfer directly.

For boards and audit committees, SBOM maturity is also becoming a reasonable proxy question for software supply chain resilience more broadly, alongside existing NCSC Cyber Assessment Framework and ISO 27001 controls. A CISO who can produce an accurate, current SBOM for critical systems on request is demonstrating exactly the kind of operational evidence that resilience testing and regulatory scrutiny increasingly demand, in the UK and the EU alike.

Executive Action:

  • Fold SBOM status into existing third-party and technology risk reporting rather than creating a separate reporting line
  • Add SBOM currency as a standing item in quarterly cyber resilience updates to the board or risk committee
  • Review INFORMD’s executive briefing library at /resources/ for related governance and technology risk frameworks

For a tailored briefing on Cyber Resilience Act and SBOM readiness, contact the INFORMD team (/contact/).

INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library (/resources/) or access our free assessment tools (/tools-assessments/).

Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk (/resources/).

What is a Software Bill of Materials (SBOM)?

An SBOM is a machine-readable inventory of every component, library, and dependency inside a piece of software. It lets organisations identify quickly whether a newly disclosed vulnerability affects their systems, which is the basis for the EU Cyber Resilience Act’s 24-hour reporting duty.

Does the UK legally require SBOMs in 2026?

No. The UK’s Software Security Code of Practice, run by the Department for Science, Innovation and Technology, encourages SBOM adoption voluntarily. UK organisations selling into the EU face the Cyber Resilience Act’s requirements regardless of domestic UK rules.

What happens on 11 September 2026 under the Cyber Resilience Act?

Manufacturers of products with digital elements sold into the EU must begin reporting actively exploited vulnerabilities to ENISA and national CSIRTs within 24 hours of discovery. Formal SBOM disclosure obligations follow later, from December 2027.

Which SBOM format should UK companies use, CycloneDX or SPDX?

Both are internationally recognised, machine-readable formats accepted under current SBOM guidance, including the 2026 CISA-led minimum elements update. The right choice usually depends on existing tooling; consistency across the software estate matters more than which format is chosen.

Similar Posts