CRA Vulnerability Management

How to find, triage, and report vulnerabilities under the CRA. SBOM generation, CVE triage, VEX statements, coordinated disclosure, and the 24-hour early-warning notification required from 11 September 2026.

Browse all articles

Vulnerability Management

ENISA on Frontier AI: 5 Consequences for the CRA

ENISA's July 2026 frontier AI paper: exploitation at machine speed. 5 consequences for Cyber Resilience Act manufacturers, from CVD floods to patch diffing.

Vulnerability Management

ENISA's Secure by Design Playbook: A CRA Guide

ENISA's Secure by Design and Default Playbook (final v1.0, July 2026) turns CRA rules into 22 practical checklists for SMEs, now also on GitHub.

Vulnerability Management

How to Generate a Firmware SBOM: Tools and Workflows

Generate a firmware SBOM using Yocto, Buildroot, EMBA, or Syft. ENISA vulnerability reporting starts September 11, 2026. Step-by-step workflows for CRA compliance.

Vulnerability Management

Generate an SBOM for CRA: Tools, Formats, CI/CD

A hands-on guide to generating Software Bills of Materials for CRA compliance. Covers open-source tools, format selection, and automated pipeline integration.

Stay in the loop

Get notified when we publish new articles about CRA compliance and product security.