What applies now
Since 11 September 2026, the duty to report actively exploited vulnerabilities applies to makers of products with digital elements. That means knowing quickly what is in your software and who changed it.
What applies from December 2027
From 11 December 2027 the full security requirements apply, including a software bill of materials and CE marking. Plan for them now, because evidence is easiest to keep as software is built.
What evidence you will need
Expect to show what your software contains and how it was developed securely. That means a software bill of materials, and records of who approved each change and what was checked before it shipped.
How EmberNest helps you evidence it
Live today: two approvals with segregation of duties on every piece of work, and evidence linked to every change. That is the change and approval record an assessor asks for.
Roadmap: exportable evidence packs. We will describe them as live once they ship. EmberNest helps you evidence compliance. It does not make you compliant or certified.
This page is not legal advice. Dates as given in our plan of 10 October 2026.
All standards