From 11 September 2026, the EU Cyber Resilience Act gives manufacturers of connected products 24 hours to file an early warning once a vulnerability is actively exploited, then a 72-hour notification and a 14-day final report to ENISA and national CSIRTs. The obligation covers products already on the EU market, and penalties reach €15 million or 2.5% of global annual turnover. The hard part is not writing the warning. It is proving, on demand, which components sit in which products and when exploitation became known. Manual vulnerability tracking and disconnected spreadsheets collapse under a 24-hour clock. Meeting the deadline calls for SBOM-level component visibility, continuous vulnerability monitoring, and audit-ready evidence generated as events unfold rather than reconstructed afterward.