No items found.
Event

Which Vulnerabilities Count? Reporting and Exploitability Under the Cyber Resilience Act

Date
10/14/2026
Time
11 am PT
Event Type
Virtual

On 11 September 2026, the Cyber Resilience Act's reporting obligation went live. If you become aware that a vulnerability in a product you sell into the EU is being actively exploited, you have 24 hours to file an early warning with ENISA and your national CSIRT, 72 hours for the details, and 14 days for a final report once a fix is available. It applies to products already on the market, not only to what you ship next year.

‍

The second date is 11 December 2027, when the rest of the regulation applies: the Annex I essential requirements, conformity assessment and CE marking, SBOMs, and support periods measured in years. No harmonized standard has been published in the Official Journal yet, and no CRA notified bodies have been designated, so the conformity route many teams are waiting on is not open. The obligations arrive on schedule regardless.

‍

Both dates come down to the same question. Which of the vulnerabilities in what you ship are actually exploitable, and can you prove it? The Commission's July 2026 guidance sharpened that question considerably. A vulnerability in a third-party component is reportable only where it is exploitable in your product, and a vulnerability counts as known once your own testing finds it, including AI-assisted analysis.

‍

In this webinar, we'll through both deadlines and what they ask of engineering and security teams. We cover:

‍

  • What the 24, 72 and 14-day reporting clock requires, and when the clock actually starts
  • Why "exploitable in your product" became a regulatory determination rather than a triage preference
  • What December 2027 adds: product classification, Annex I, SBOM depth, and the support-period long tail
  • How to build the evidence now, without waiting for harmonized standards

‍

GPT-6.1 Sol on Codex: Astra-level security, a third faster, zero cheating
Nine days after GPT-6 Sol, Codex with GPT-6.1 Sol scores 77.7% FuncPass and 34.1% SecPass — within one task of GPT-6 Astra on security, a third faster, and with zero confirmed cheating.
Read more
GPT-6 Sol on Codex: average scores, quarter the cost
Codex with GPT-6 Sol scores 72.1% FuncPass and 25.1% SecPass for $104 on Azure — 78% cheaper than Astra ($468) — with zero confirmed cheating.
Read more
Opus 5.5: 6x cheaper and 2x faster than Fable 5.1, but only 33.5% of code is secure
Claude Code with Opus 5.5 finishes coding tasks in a median of 2.2 minutes for $116 in total, the fastest run on our board and the cheapest Anthropic run by far, but lands at only 33.5% for secure code.
Read more
GPT-6.1 Sol on Codex: Astra-level security, a third faster, zero cheating
Nine days after GPT-6 Sol, Codex with GPT-6.1 Sol scores 77.7% FuncPass and 34.1% SecPass — within one task of GPT-6 Astra on security, a third faster, and with zero confirmed cheating.
Read more
GPT-6 Sol on Codex: average scores, quarter the cost
Codex with GPT-6 Sol scores 72.1% FuncPass and 25.1% SecPass for $104 on Azure — 78% cheaper than Astra ($468) — with zero confirmed cheating.
Read more
Opus 5.5: 6x cheaper and 2x faster than Fable 5.1, but only 33.5% of code is secure
Claude Code with Opus 5.5 finishes coding tasks in a median of 2.2 minutes for $116 in total, the fastest run on our board and the cheapest Anthropic run by far, but lands at only 33.5% for secure code.
Read more

Want to stay in the loop?

Sign up for our newsletter.