Image: reversinglabs.com · rights & removal
CRA compliance will be judged by the binary you ship
Reporting by ReversingLabs BlogRead the original at reversinglabs.com
Executive Summary
Facts Only
* Manufacturers must report actively exploited vulnerabilities and severe incidents in products already on the EU market, including legacy releases, after September 11, 2026.
* Full application of CRA requirements is due on December 11, 2027.
* Annex I requirements describe properties of shipped bytes, such as "Delivered without any known exploitable vulnerabilities" and exploitation mitigation measures like ASLR, DEP, stack canaries, and RELRO.
* Build-system SBOMs often exclude statically linked or repackaged components, creating an inaccuracy in component documentation.
* An assessment of a commercial network appliance found 41.4% of bill-of-materials entries lacked a package URL.
* In the assessed network appliance, 1,976 binaries shipped without ASLR, and 156 files combined known CVEs with missing memory protection.
* The assessment revealed that a product shipped private keys in cleartext and contained 18 distrusted root certificate authorities.
* Compared to the prior version, a release closed 351 vulnerability instances and introduced 36 supportive findings for remediation.
* The evidence related to known exploited vulnerabilities (KEV) should trigger Article 14 reporting readiness.
Full Take
From the original · ReversingLabs Blog
Spectra Assure Free Trial Get your 14-day free trial of Spectra Assure for Software Supply Chain Security Get Free TrialMore about Spectra Assure Free TrialMany organizations still talk about the EU Cyber Resilience Act (CRA) as a 2027 problem. It stopped being one on Sept.Read the full story at reversinglabs.com
Sentinel — Human
The text functions as a highly focused, expert-driven argument advocating for artifact-level evidence over procedural documentation in supply chain security compliance, grounded in specific regulatory context.
