Header image

EU Cyber Resilience Act to impose new software security obligations

The EU Cyber Resilience Act will soon require all software vendors selling products with digital elements into the EU to report vulnerabilities within 24 hours of discovery, according to Bleeping Computer.

Starting September 11, 2026, manufacturers must notify ENISA of actively exploited vulnerabilities within 24 hours and provide a full report within 72 hours. This initial reporting obligation precedes the engineering requirements of the act, which take effect on December 11, 2027. 

The law emphasizes the need for current software bills of materials (SBOMs), moving beyond one-time compliance artifacts to dynamic records. With 98% of applications containing open-source components, nearly all manufacturers are affected. The act aims to close the gap between rapid vulnerability disclosure and the average 55-day remediation time for critical vulnerabilities. 

Companies can address this by integrating automated SBOM regeneration and documented vulnerability handling processes into their pipelines, or by utilizing pre-vetted components with established provenance. The EU CRA will enforce these requirements at scale, posing a significant challenge for organizations that cannot quickly ascertain their software inventory and known vulnerabilities.

Source: Bleeping Computer

Kelley Damore
Kelley Damore Chief Content Officer CyberRisk Alliance

Kelley Damore is Chief Content Officer at CyberRisk Alliance, where she leads content strategy across the company’s digital brands, research, communities and live events serving CISOs and security practitioners. At CyberRisk Alliance, she is focused on delivering 365-day engagement, trusted journalism and actionable insights to help security leaders navigate an increasingly complex threat landscape.

Kelley Damore
Kelley Damore Chief Content Officer CyberRisk Alliance

Kelley Damore is Chief Content Officer at CyberRisk Alliance, where she leads content strategy across the company’s digital brands, research, communities and live events serving CISOs and security practitioners. At CyberRisk Alliance, she is focused on delivering 365-day engagement, trusted journalism and actionable insights to help security leaders navigate an increasingly complex threat landscape.

Upcoming Events

No events found.