Breaking
SecurityDeveloping Story

EU CRA ends manual vuln triage

Security experts say the EU Cyber Resilience Act's 24-hour reporting mandate makes manual vulnerability triage obsolete and forces global vendors to automate or risk losing market access.

··3 hours ago·6 min read
blue and white star print textile
Photo by Christian Lue on Unsplash

The EU Cyber Resilience Act (CRA) is not just another compliance checkbox. According to independent security experts, it is reshaping international technology markets by making cyber resilience a mandatory baseline for market entry. At the heart of the regulation is a 24-hour reporting requirement for actively exploited vulnerabilities or severe incidents affecting products with digital elements — a clock that experts say renders traditional manual triage completely untenable.

The reporting mandate, introduced on Sept. 11, establishes an EU-wide product-security law for internet-connected hardware and software. Its scope is broad: security software, identity-management systems, operating systems, routers, firewalls, network management systems, VPNs, and more. And it applies even if a company is headquartered outside the EU, giving the regulation extraterritorial reach that experts say will force global suppliers to rethink how they build and monitor their products.

From design to market access

Vincent Lomba, chief product security officer at Alcatel Lucent Enterprise, sees the CRA's reporting rules turning security into a mandatory baseline for market entry anywhere, not just in Europe. He points out that the regulation's impact will extend beyond Europe and affect a wide range of technology markets, including the hardware running modern AI workloads.

“Manufacturers are currently prioritising raw processing power over built-in resilience,” says Lomba. “That can no longer be the case.”

— Vincent Lomba, chief product security officer at Alcatel Lucent Enterprise

Lomba adds that global hardware and GPU providers must soon update their core architectures to integrate comprehensive cyber resilience from the ground up in order to maintain European market access. The regulations mean that firms doing business in Europe will be obliged to build security directly into their products from the design phase, giving them a competitive advantage over those that don't. That advantage will confer in particular to European firms, he says.

“These rules will establish a new international benchmark. It will force tech suppliers around the world to up their resilience practices in order to continue to compete with the European supply chain,” he adds.

Learning from GDPR's mistakes

Other experts compared the rules introduced through the CRA to the changes that came with the adoption of the EU’s General Data Protection Regulation (GDPR). Artem Serebrov, director of product at PCA Cyber Security, says there are parallels to be drawn between the current state of the Cyber Resilience Act and the early days of GDPR rules.

But Serebrov warns that the parallel may include follow-on effects that could undermine the very purpose of the legislation. He notes that under GDPR, obligations to report data leakage were introduced without obligations to measure data loss, which invited companies to softly limit the extent to which they were monitoring data loss in the interest of avoiding hefty GDPR-related fines. The implication is that the CRA could face similar gaming unless measurement obligations are built in.

Manual triage is dead

One significant issue is that the information needed to file a CRA notification usually lives in five or six different places at once: security information and event management (SIEM) systems, threat feeds, known exploited vulnerability (KEV) alerts, scanner findings, asset inventories, and software bills of materials (SBOMs), none of which have been built to talk to one another on a readily compliant 24-hour timeline.

Joe Brinkley, director of offensive security research and community at penetration testing as a service vendor Cobalt, warns that the 24-hour reporting clock “completely kills manual triage” procedures for vendors obliged to comply with the new regulations.

“You just can’t expect an analyst to catch a KEV alert, manually grep a static SBOM, and then dig through SIEM logs to see if a box is actively taking fire,” he says.

— Joe Brinkley, director of offensive security research and community at Cobalt

Faced with tight reporting deadlines, vendors must wire these isolated silos of security alerts together — an operational follow-on obligation of the regulation. Brinkley advises that the second a vulnerability drops, the infrastructure needs to automatically query the SBOM, pinpoint the affected assets, and cross-reference live telemetry to confirm exploitation. If that discovery phase isn't automated, he says, the team will spend 23 hours hunting for ground truth across five different dashboards instead of actually pushing patches.

Operational readiness under scrutiny

Louise Horton, head of UK government affairs at cybersecurity consultancy NCC Group, argues that reporting requirements introduced through the CRA will be the first real test of operational readiness for many organisations.

“Success will depend on having mature vulnerability management processes, visibility across products and dependencies, and the ability to identify, assess, and report security issues quickly and accurately,” Horton says.

— Louise Horton, head of UK government affairs at NCC Group

Horton adds that those most prepared will have already embedded secure-by-design principles into product development and established strong governance across their software and supply chains. Rather than treating compliance as a series of isolated obligations, organisations should view these requirements as part of a broader cyber resilience strategy, she notes.

Heigor Freitas, head of region (UK and Europe) of industry group CREST, argues the EU CRA will strengthen the foundation of the digital ecosystem. He says it will encourage organisations within scope of the CRA, including software and hardware manufacturers, to strengthen processes, improve accountability, and embed security more consistently throughout their practices.

The CISO's new burden

That pressure, Cobalt's Brinkley argues, will fall directly on their CISOs. He says the CRA rips vulnerability reporting right out of the legal department and drops it directly into live security ops, and that the 24-hour window is brutal. If you lack absolute, real-time ground truth about your software supply chain, he warns, you are going to fail the requirement.

The CRA will drive a new baseline for visibility for enterprise security professionals as well, because they will need to have a much better understanding of their software and hardware infrastructure. Brinkley warns that taking three days to figure out if you're exposed to a zero-day is a luxury nobody has anymore.

He adds that SBOMs will have to get agile. CISOs have to stop treating SBOMs and asset lists like dead compliance PDFs, he says. They need to be live data structures that are queried constantly through the engineering pipeline to drive immediate mitigation, rather than just using them to check a compliance box once a quarter.

What this means for businesses

The CRA's 24-hour reporting requirement is not just a regulatory hurdle; it is a fundamental shift in how security operations must function. For businesses selling into the EU, the message is clear: manual, siloed vulnerability management is no longer viable. The regulation effectively mandates automation and real-time visibility across the software supply chain.

This could mean that companies without mature, integrated security tooling will struggle to comply, potentially losing access to the European market. Conversely, firms that invest in secure-by-design principles and automated SBOM querying may gain a competitive edge. As Lomba notes, these rules will establish a new international benchmark, forcing tech suppliers worldwide to up their resilience practices to compete with the European supply chain.

For CISOs, the burden is immediate. They must transform SBOMs and asset inventories from static documents into live, queryable data structures. They must ensure that the moment a vulnerability is disclosed, their infrastructure can automatically check for exposure and confirm exploitation. Anything less, Brinkley warns, will result in failure.

The CRA also serves as a cautionary tale: as Serebrov points out, GDPR's reporting obligations without measurement obligations led to perverse incentives. If the CRA does not include robust measurement requirements, companies might similarly limit their monitoring to avoid triggering reporting thresholds. That could undermine the regulation's goal of improving cyber resilience.

Ultimately, the EU CRA is testing whether organisations can turn security into a continuous, automated process rather than a periodic compliance exercise. Those that succeed will be better prepared for the inevitable next vulnerability — and better positioned to compete in a market where resilience is no longer optional.

#eu cra#vulnerability management#compliance#sbom#cyber resilience

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories