Skip to main content
Policy Security

EU Cyber Resilience Act vulnerability reporting obligations take effect

The EU Cyber Resilience Act's vulnerability reporting obligations to ENISA arrive on September 11, according to an OpenSSF tech talk recap. The full regulation lands in December 2027. OpenSSF cited a 2026 readiness report finding 66% of respondents still unfamiliar with the regulation, with only 41% of manufacturers expecting full compliance by the deadline. Under the CRA, maintainers who do not monetize projects carry no obligations, while manufacturers consuming open source bear due diligence, upstream contribution and incident reporting duties. OpenSSF published steward and maintainer checklists, and its ORBIT Launchpad group released manufacturer baseline catalogs.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Open Source Security Foundation and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

Chrome 153 fixes actively exploited V8 flaw

Google released Chrome 153 to the stable channel with fixes for 230 vulnerabilities, including CVE-2026-87491, an out-of-bounds write flaw in the V8 JavaScript and WebAssembly engine. Google says an exploit for the medium-severity...