# EU Cyber Resilience Act vulnerability reporting obligations take effect

_Thursday, September 10, 2026 at 8:00 PM EDT · Policy, Security · Latest · Tier 2 — Notable_

The EU Cyber Resilience Act's vulnerability reporting obligations to ENISA arrive on September 11, according to an OpenSSF tech talk recap.

The full regulation lands in December 2027. OpenSSF cited a 2026 readiness report finding 66% of respondents still unfamiliar with the regulation, with only 41% of manufacturers expecting full compliance by the deadline. Under the CRA, maintainers who do not monetize projects carry no obligations, while manufacturers consuming open source bear due diligence, upstream contribution and incident reporting duties.

OpenSSF published steward and maintainer checklists, and its ORBIT Launchpad group released manufacturer baseline catalogs.

## Sources

- [Open Source Security Foundation](https://openssf.org/blog/2026/09/10/tech-talk-recap-a-practitioners-guide-to-cra-readiness/)

---
Canonical: https://techandbusiness.org/newswire/zLxrDPuJWcNiwX1iMwAtR2
Retrieved: 2026-09-11T03:31:41.231Z
Publisher: Tech & Business (techandbusiness.org)
