[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fNjY2-1hcWvc5dSRCRDlh0wm9V709DSljMpeogj5vSj4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"da085e86-c653-4a05-b3c8-33812edac556","eu-cyber-resilience-act-activates-mandatory-vulnerability-reporting","abf92bb8-01f8-4f45-8a02-1fadd3c3e174","EU Cyber Resilience Act Activates Mandatory Vulnerability Reporting","The EU Cyber Resilience Act (CRA) introduces strict, time-bound obligations for manufacturers to report actively exploited vulnerabilities and security incidents in products sold within the EU. Organizations that fail to build structured vulnerability disclosure and incident reporting pipelines risk non-compliance penalties and reputational harm. The act also creates new responsibilities for open-source maintainers whose software is embedded in commercial products, expanding the compliance surface beyond traditional software vendors. This matters because it signals a global regulatory shift where security transparency is no longer optional — it is legally mandated with enforceable deadlines.","**Immediate actions:**\n- Conduct a product inventory audit to identify all software and hardware sold in the EU that falls under CRA scope.\n- Establish a documented vulnerability reporting workflow with defined roles, escalation paths, and reporting deadlines aligned to CRA timelines.\n\n**Long-term improvements:**\n- Implement a continuous vulnerability management program that tracks CVEs and actively exploited vulnerabilities across your entire product portfolio.\n- Develop a Software Bill of Materials (SBOM) for all commercial products to surface open-source dependencies that may trigger CRA obligations.\n- Embed CRA compliance requirements into the Software Development Lifecycle (SDLC) and vendor contracts to ensure supply chain accountability.\n\n**Detection & monitoring measures:**\n- Deploy automated threat intelligence feeds to detect active exploitation of vulnerabilities in your products as early as possible.\n- Establish a Security Operations Center (SOC) workflow specifically mapped to CRA incident classification and notification thresholds.",[12,13,14,15,16,17,18,19,20,21],"NIST SP 800-61 (Incident Response)","NIST SP 800-53 RA-5 (Vulnerability Monitoring and Scanning)","NIST SP 800-53 IR-6 (Incident Reporting)","CIS Control 7: Continuous Vulnerability Management","CIS Control 17: Incident Response Management","EU Cyber Resilience Act (CRA) Articles 11, 13, and 14","GDPR Article 33 (Breach Notification — parallel obligation)","ISO\u002FIEC 27001:2022 Annex A.5.24 (Incident Management Planning)","ENISA Good Practices for Security of IoT","NTIA Minimum Elements for an SBOM","published","2026-10-01T12:20:18.117405+00:00","2026-10-01T12:20:17.746+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fcheckmarx.com\u002Fzero-post\u002Fthe-cyber-resilience-acts-new-reporting-obligations-are-active-what-you-should-know\u002F","the-cyber-resilience-act-s-new-reporting-obligations-are-active-what-you-should--fd9374","The Cyber Resilience Act’s New Reporting Obligations Are Active: What You Should Know",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",[]]