[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_3UrSnqidEiYVbgANKdDyDi7y1qNppAyGKsZAwwDt5A":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"68f0fdc4-5af8-43b2-8d70-0e41a6f391a6","eu-cra-mandates-24-hour-vulnerability-disclosure-and-sboms-for-software-vendors","c078c200-5917-4457-9ca2-f84997d05663","EU CRA Mandates 24-Hour Vulnerability Disclosure and SBOMs for Software Vendors","The EU Cyber Resilience Act (CRA), effective September 2026, transforms vulnerability disclosure from a voluntary best practice into a legal obligation, requiring vendors to report actively exploited vulnerabilities within 24 hours of discovery. Many organizations currently lack the internal processes, tooling, and supply chain visibility needed to meet this timeline consistently. The mandatory use of Software Bills of Materials (SBOMs) exposes a widespread gap: vendors often cannot accurately account for every component that has shipped in their products. Failure to comply carries significant legal and financial risk, making this a board-level concern rather than a purely technical one. Organizations that delay preparation will find themselves scrambling to retrofit compliance into immature vulnerability management programs.","**Immediate actions:**\n- Conduct a gap assessment against CRA requirements, focusing specifically on your current vulnerability discovery-to-disclosure timelines.\n- Inventory all shipped software products and begin generating SBOMs using tools such as Syft, CycloneDX, or SPDX-compatible solutions.\n\n**Compliance & Process improvements:**\n- Establish a formal vulnerability disclosure policy and internal escalation procedure that can reliably meet the 24-hour reporting window.\n- Designate a cross-functional CRA compliance team including legal, security, and product engineering to own ongoing obligations.\n- Integrate SBOM generation into the CI\u002FCD pipeline so every release automatically produces and archives an up-to-date component manifest.\n\n**Detection & Monitoring measures:**\n- Deploy continuous software composition analysis (SCA) scanning to detect newly disclosed CVEs affecting shipped components in near real-time.\n- Subscribe to authoritative vulnerability feeds (NVD, vendor advisories, CISA KEV) and automate alerting tied directly to your SBOM inventory.\n- Log and timestamp all vulnerability discovery events to create an auditable record demonstrating when your organization first became aware of an issue.",[12,13,14,15,16,17,18,19,20,21],"EU Cyber Resilience Act (CRA) — Article 11 (Vulnerability Reporting Obligations)","EU Cyber Resilience Act (CRA) — Annex I (Essential Cybersecurity Requirements)","NIST SP 800-161r1 — Supply Chain Risk Management","NIST CSF 2.0 — GV.OC, ID.RA, RS.CO","CIS Control 2 — Inventory and Control of Software Assets","CIS Control 7 — Continuous Vulnerability Management","NTIA SBOM Minimum Elements Guidance","ISO\u002FIEC 27001:2022 — A.8.8 Management of Technical Vulnerabilities","GDPR Article 33 (Notification to supervisory authority — analogous disclosure timeline precedent)","CISA KEV (Known Exploited Vulnerabilities Catalog)","published","2026-09-08T22:22:14.741541+00:00","2026-09-08T22:22:14.449+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fthe-eu-cras-real-question-what-shipped-and-when-did-you-know\u002F","the-eu-cra-s-real-question-what-shipped-and-when-did-you-know-c5c4ae","The EU CRA's Real Question: What Shipped, and When Did You Know?",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]