As of September 11, 2026, the EU Cyber Resilience Act's (CRA) vulnerability and incident reporting obligations are live. If you make, import, or distribute products with digital elements sold in the EU, this applies to you... regardless of where you're based. Non-EU companies must comply to access the EU market at all.
The CRA shifts the burden of proof: you can no longer claim your software is secure; you must prove it. You must now detect, report, and fix actively exploited vulnerabilities within 24 hours, with a full technical report to your national Computer Security Incident Response Team (CSIRT) and European Union Agency for Cybersecurity (ENISA) within 72 hours. Non- compliance carries fines up to €15 million or 2.5% of worldwide annual turnover, plus the threat of market exclusion.
The question isn't whether you can find vulnerabilities. It's whether you can find the ones that matter, fix them fast enough to beat the clock, and produce the evidence regulators expect.
Veracode maps directly to each CRA requirement: SAST and SCA catch exploitable flaws with documented findings, the SBOM API keeps a live inventory of every dependency, Reachability Analysis identifies which flaws are actually reportable, and Veracode Fix makes remediation up to 3X faster. This is the work we've done for two decades, across 47 million scans and 148 million flaws fixed.
No comments:
Post a Comment