#introduction I work on software supply-chain evidence, and I have one argument I would like to be wrong about. The CRA's two dates get planned in the wrong order. Reporting an exploited vulnerability within 24 hours starts 11 September 2026. The machine-readable SBOM is only required from 11 December 2027 — fifteen months after the clock starts. On a 24-hour clock the first question is not how to word the notification. It is which of your services ship the component. #CRA #SBOM