Skip to main content
Policy Security

EU Cyber Resilience Act vulnerability reporting obligations take effect

The EU Cyber Resilience Act's vulnerability reporting obligations to ENISA arrive on September 11, according to an OpenSSF tech talk recap. The full regulation lands in December 2027. OpenSSF cited a 2026 readiness report finding 66% of respondents still unfamiliar with the regulation, with only 41% of manufacturers expecting full compliance by the deadline. Under the CRA, maintainers who do not monetize projects carry no obligations, while manufacturers consuming open source bear due diligence, upstream contribution and incident reporting duties. OpenSSF published steward and maintainer checklists, and its ORBIT Launchpad group released manufacturer baseline catalogs.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Open Source Security Foundation and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Infrastructure Products
Infrastructure Products

Blackstone's AirTrunk in talks for S$2B loan to fund Singapore REIT listing

AirTrunk, the data center operator owned by Blackstone Inc., is in talks with banks to borrow about S$2 billion (US$1.6 billion) to help finance the public listing of a real estate investment trust backed by its assets, according ...

AI Infrastructure
AI Infrastructure

AWS makes SageMaker HyperPod model caching generally available

Amazon Web Services said model caching for SageMaker Inference on HyperPod is now generally available in all regions where HyperPod is offered. The feature pre-loads model weights and inference-server container images onto cluste...