ActiveState

Under the EU CRA, unvouched open source is a market risk, not just a security gap

Your digital products run on open source software your team didn't write, and the EU CRA asks for diligence and attestation that it is secure. While AI helps your developers code faster, it pulls in open source packages without oversight. Starting September 11, 2026, the EU CRA requires you to report actively exploited vulnerabilities in your product, ahead of the full compliance deadline in December 2027. Non-compliance puts your EU market access at risk.

Talk to an expert

Engineering owns the data

OSS governance has always been an engineering problem, and the EU CRA just put a deadline on it that lands on your roadmap.

September 11, 2026 is when the reporting clock starts for actively exploited vulnerabilities. But teams can realistically only file that report in time by already knowing what's in their products.
Most SBOM processes today only capture direct dependencies. But 64% of your open source is transitive, not chosen directly, and that's exactly where an exploited vulnerability is likely to surface.
A governed OSS inventory, current SBOM coverage, and an audit trail for every remediation decision are due in full by the EU CRA's December 2027 compliance deadline, and will become ongoing overhead on every release after that, indefinitely.
Developer time today vs. with ActiveState: up to 30% capacity reclaimed
Package provenance: signed SBOM, cryptographic signature, full build provenance, and license compliance for every artifact

Security owns the deadline

Security teams are handed a compliance obligation only possible to meet if their engineering teams prioritize things they’ve never been formally asked to do. Your organization will need a defined process that survives an audit, not a business practice that relies on individual memory.

The EU CRA requires a documented vulnerability handling workflow covering intake, triage, remediation, and disclosure that can be demonstrated to a regulator.
Meeting the EU CRA's 24-hour and 72-hour deadlines is only realistic if you already know what's in your product before a disclosure happens.
The EU CRA requires an answer scanners aren’t built to provide: What was in your product? When did you know? What did you do? And how long did it take?

The EU CRA makes it a shared obligation between Security and Engineering

Meeting the EU CRA's compliance demands is what protects your organization's EU market access.

54 days

Industry average for critical CVE remediation.

Source: Edgescan 2026
60%

of breaches exploit a known, already-patched vulnerability.

Source: Verizon DBIR 2026
64%

of open source components in production are transitive, and your team didn't choose them directly.

Source: Black Duck OSSRA 2025

Employing a Curated Catalog

The ActiveState Curated Catalog aligns Security and Engineering on a single EU CRA compliance effort. It gives you a private, pre-vetted source of open source software, so fewer vulnerabilities ever reach your build in the first place. Security teams get full provenance and mitigated exposure. Engineering teams stop pausing sprints for security work.

Curated Catalog: vetted, built-from-source packages flowing into your existing tools

Automated, current SBOMs across every build

Cryptographic attestation and verifiable provenance, for every component

5-day Critical CVE remediation SLA
10 days for Highs, 30 for all others

Explore CRA Further

AI Coding and Open Source Risk: What the Data Actually Shows About Remediation Debt

Watch Webinar