Vulnerability Management
VEX for CRA: Vulnerability Exploitability eXchange Guide
How to use VEX (Vulnerability Exploitability eXchange) for CRA compliance: formats, status types, SBOM integration, and practical examples.
How to find, triage, and report vulnerabilities under the CRA. SBOM generation, CVE triage, VEX statements, coordinated disclosure, and the 24-hour early-warning notification required from 11 September 2026.
How to use VEX (Vulnerability Exploitability eXchange) for CRA compliance: formats, status types, SBOM integration, and practical examples.
Does ISO 27001 cover the Cyber Resilience Act? Not fully. Maps the exact gaps, what your ISMS transfers, and what you still need before the 2027 deadline.
Get notified when we publish new articles about CRA compliance and product security.