The EU CRA’s Real Question: What Shipped, and When Did You Know?

The EU CRA’s Real Question: What Shipped, and When Did You Know?
The article explains how a suspicious vulnerability disclosure to an open source maintainer illustrates the same visibility and reporting challenges that many software vendors will face under the EU Cyber Resilience Act. It argues that companies must know what shipped, when they learned of vulnerabilities, and how quickly they can prove it before the CRA’s reporting clock begins. #EUCyberResilienceAct #ENISA #ActiveState

Keypoints

  • A maintainer received a 95-vulnerability report that was mostly false but still required full review.
  • The EU Cyber Resilience Act will require rapid vulnerability reporting to ENISA starting September 11, 2026.
  • Full engineering requirements under the CRA take effect later, on December 11, 2027.
  • Most organizations struggle to keep SBOMs current and to prove what software actually shipped.
  • Companies are responding by automating provenance and SBOM generation or by using pre-vetted components.

Read More: https://www.bleepingcomputer.com/news/security/the-eu-cras-real-question-what-shipped-and-when-did-you-know/