Cyber Resilience Act
The CRA from the side of those who make software: 24-hour early warning, SBOMs, and a maturity score that is not proof of conformity.
From 11 September 2026, Article 14 of the Cyber Resilience Act requires an early warning within 24 hours for exploited vulnerabilities, and there will be no dress rehearsal. The CRA interests me because it is the most concrete rule in the European package: SBOMs, vulnerability handling, updates for the whole life of the product are things a team either can do or cannot. A maturity score is not conformity, a questionnaire is not an inventory. I write about what is actually needed, before the deadline.