The EU Cyber Resilience Act (CRA) is approaching with two key compliance deadlines: September 2026 for vulnerability reporting obligations and December 2027 for all major requirements. The regulation applies to virtually all connected software sold in the EU, with no distinction between human-written and AI-generated code. Core mandates include secure-by-design practices, lifecycle vulnerability management, SBOM generation, and 24-hour reporting of actively exploited vulnerabilities to ENISA. Organizations are advised to immediately inventory software and dependencies, document secure development practices, and implement SBOM tooling. 'The AI did it' is explicitly not a valid defense for security flaws under the CRA.
Table of contents
The broad scope and core shiftKey provisions on the booksAccountability across the organizationWhat to audit and prioritize todayFrom burden to competitive advantage203 Impressions