September 11: The CRA’s First Milestone for Product Vulnerability Reporting
11 Sep 2026

September 11: The CRA’s First Milestone for Product Vulnerability Reporting

Date
11 Sep 2026 10:00h - 11:00h
Day
Friday

Description

From 11 September 2026, manufacturers of products with digital elements will face new reporting obligations under the Cyber Resilience Act (CRA) for actively exploited vulnerabilities.

Meeting these requirements goes beyond understanding the regulation. Product teams need reliable and up-to-date visibility into the components that make up their products and the vulnerabilities that may affect them. This is why integrating product security information into the software development lifecycle and CI pipelines becomes essential.

In this webinar, we will explore why this integration matters and how it supports a more reliable and efficient vulnerability reporting process. We will look at the challenges of maintaining accurate SBOMs as products evolve, how vulnerability data can be transformed into evidence for CRA compliance, and how different standards and formats can support this process.

We will also discuss the role of the ENISA single reporting platform and how it fits into the broader vulnerability management and reporting workflow.

Topics covered:

  • What the CRA means for product and engineering teams
  • Why static SBOMs are not enough and why generating them from CI pipelines matters
  • Turning vulnerability information into actionable CRA evidence
  • CSAF, VEX, Vulnerability Disclosure Portals and CRA technical documentation
  • The ENISA single reporting platform and its role in vulnerability reporting

The session is aimed at Product Security, DevSecOps, PSIRT and Vulnerability Management teams, as well as professionals responsible for product cybersecurity and CRA compliance.