DEV Community

Cover image for When Does the CRA's 24-Hour Reporting Clock Actually Start?
Maria
Maria

Posted on

When Does the CRA's 24-Hour Reporting Clock Actually Start?

The Cyber Resilience Act (CRA) introduces a requirement that many engineering teams are still trying to operationalize: report actively exploited vulnerabilities and incidents within 24 hours.

At first glance, that sounds straightforward. Until you ask one simple question:

  • When does that 24-hour clock actually start? -Is it when a vulnerability appears in your Software Bill of Materials (SBOM)?
  • When your Software Composition Analysis (SCA) tool raises an alert?
  • When an exploit becomes public?
  • Or only after you've confirmed that your product is actually affected?

For many organizations, those are very different moments.

๐…๐ข๐ง๐๐ข๐ง๐  ๐š ๐ฏ๐ฎ๐ฅ๐ง๐ž๐ซ๐š๐›๐ข๐ฅ๐ข๐ญ๐ฒ ๐ข๐ฌ๐ง'๐ญ ๐ญ๐ก๐ž ๐ฌ๐š๐ฆ๐ž ๐š๐ฌ ๐ก๐š๐ฏ๐ข๐ง๐  ๐š๐ง ๐ข๐ง๐œ๐ข๐๐ž๐ง๐ญ

Modern development teams receive thousands of security findings every week.

Most come from:

  • Software Composition Analysis (SCA)
  • SBOM scanning
  • Dependency monitoring
  • Container image scanning
  • Secret detection

The challenge isn't finding vulnerabilities anymore.

The challenge is determining which findings actually require action.

Without a structured workflow, teams either:

  • waste valuable time investigating non-issues,
  • or worse, miss the moment when a vulnerability becomes a reportable incident.

๐“๐ก๐ž ๐ฆ๐ข๐ฌ๐ฌ๐ข๐ง๐  ๐ฉ๐ข๐ž๐œ๐ž: ๐œ๐จ๐ง๐ญ๐ž๐ฑ๐ญ

An SBOM tells you what components you use.

SCA tells you which components are vulnerable.

But neither automatically tells you:

  • Is the vulnerable code actually reachable?
  • Is it exploitable in your environment?
  • Which product versions are affected?
  • Who should be notified?
  • Has the CRA notification clock started?

Answering those questions requires more than vulnerability scanningโ€”it requires a repeatable incident response workflow.

A practical session for engineering and security teams

If you're working in:AppSec, DevSecOps, Platform Engineering, Product Security, Vulnerability Management

Xygeni & SecureHabits are hosting a free live webinar where we'll walk through a practical approach to CRA notification readiness.

We'll cover:

  • Generating and using SBOMs
  • Prioritizing SCA findings
  • Reachability and exploitability analysis
  • Notification workflows
  • What actually triggers the CRA's 24-hour ENISA reporting requirement

๐Ÿ“…๐‰๐ฎ๐ฅ๐ฒ ๐Ÿ‘๐ŸŽ
๐Ÿ•Ÿ๐Ÿ๐Ÿ”:๐Ÿ‘๐ŸŽ ๐‚๐„๐’๐“

Register here๐Ÿ‘‰https://www.linkedin.com/events/7483444225196515328/

Whether your organization is already preparing for the CRA or just beginning to understand its impact, the goal is to leave with a workflow you can applyโ€”not just another compliance checklist.

Top comments (0)