Wednesday, September 16, 2026

The EU CRA's reporting deadline is now live. Can you prove compliance?

 
 
 
Blog
 
The EU Cyber Resilience Act:
 
Find the flaws that matter, fix them within 24 hours, and prove compliance to regulators.
 
 
 

As of September 11, 2026, the EU Cyber Resilience Act's (CRA) vulnerability and incident reporting obligations are live. If you make, import, or distribute products with digital elements sold in the EU, this applies to you... regardless of where you're based. Non-EU companies must comply to access the EU market at all.

The CRA shifts the burden of proof: you can no longer claim your software is secure; you must prove it. You must now detect, report, and fix actively exploited vulnerabilities within 24 hours, with a full technical report to your national Computer Security Incident Response Team (CSIRT) and European Union Agency for Cybersecurity (ENISA) within 72 hours. Non- compliance carries fines up to €15 million or 2.5% of worldwide annual turnover, plus the threat of market exclusion.

The question isn't whether you can find vulnerabilities. It's whether you can find the ones that matter, fix them fast enough to beat the clock, and produce the evidence regulators expect.

Veracode maps directly to each CRA requirement: SAST and SCA catch exploitable flaws with documented findings, the SBOM API keeps a live inventory of every dependency, Reachability Analysis identifies which flaws are actually reportable, and Veracode Fix makes remediation up to 3X faster. This is the work we've done for two decades, across 47 million scans and 148 million flaws fixed.

 
 
 
 

Book time with Veracode to map your AppSec program against the CRA — see where you're already ahead and find your gaps.

 
 

Tuesday, September 15, 2026

🚀 What's next for the Veeam platform you trust?

 

Monday, September 14, 2026

Why verification outside the model matters more as AI-generated code scales

 
 
 
Webinar
 
AI Code Risk Is Not Uniform
 
The 2026 findings show where AI performs better, where it struggles, and where stronger verification matters most.
 
 
 

The headline number matters. The blind spots matter even more.

In the 2026 GenAI Code Security Report, AI-generated code shows major variation by vulnerability class. Some issues are handled relatively well. Others remain persistent weak points. That means the real control question is no longer “Do we allow AI- generated code?” It is “Where do we require independent verification, and how do we enforce it consistently?”

This is especially relevant for security leaders balancing secure delivery with regulatory accountability. If your development workflows assume the model is the control, your risk posture is built on weak assumptions.

Join this live webinar to learn how the findings should influence:

  • Control design for AI-assisted development
  • Release-gate policies for high-risk code paths
  • Prioritization for the classes most likely to evade model reasoning
  • Alignment across security, engineering, risk, and compliance

We will also discuss how stronger visibility, faster remediation, and software supply chain protections help organizations manage AI-driven development with more confidence and less friction.