ActiveState

OSS governance has always been an engineering problem. The EU CRA just set a deadline on it.

96% of applications containing open source include a component with a known vulnerability. Starting September 11, 2026, the EU CRA requires you to report actively exploited vulnerabilities. That depends on already knowing what's in your product.

While security is handed EU CRA obligations, engineering gets handed the bill.

SPRINT 24 25 26
CRA
CRA
CRA

It creates sprint work you didn’t plan for

The EU CRA isn't a one-time audit due in 2027. Article 14, requiring reporting for actively exploited vulnerabilities, goes live September 11, 2026. Meeting it means already running an operational process most teams haven’t built. After the December 2027 deadline, that process will show up as sprint capacity and senior engineering time pulled off of roadmap work, indefinitely.

AI-generated commits
In build path
247
Vetted
31

While AI agents pull packages faster than you can vet them

Developers using AI coding tools pull open source packages into build paths faster than any team can vet them by hand. Every unvetted package, and every transitive dependency it brings with it, widens the SBOM gap: the distance between what's actually running in production and what your organization could defend in an audit.

Security
Engineering
NOT RESOURCED
SBOM audit

And security deadlines become your backlog

Security owns EU CRA compliance requirements, but engineering owns the actual implementation. Without a governed package layer sitting between them, security ends up asking for audit trails and documentation engineering was never resourced to produce.

Not sure where your build path stands? Find out in five minutes.

Take the EU CRA Engineering Readiness Assessment

The technical deliverables the EU CRA expects from your build path:

What this puts on your roadmap
Four workstreams, no owner assigned, one date you don't control
≈9 eng-weeks
to first evidence
Ref Workstream Owner Est.
Definition of done

Covering your direct dependencies kept current as your dependency graph changes. Transitive dependencies, accounting for 64% of production open source, aren’t part of the legal minimum, but they’re usually where actively exploited vulnerabilities arise.

SPDX · CycloneDX format: spdx-2.3 scope: transitive refresh: on-build
Definition of done

An auditable intake, triage, remediation, and disclosure process, with trigger criteria defined in advance to support the 24-hour early warning window.

Process owners: named sla: defined window: 24h
Definition of done

Proof of origin and verifiable build environments for every open source component shipped inside your product.

Attestation provenance: signed build: reproducible
Definition of done

Committed security updates and defined remediation SLAs for your product’s expected lifetime.

Commitment lifetime: committed updates: enforced

Why your current tooling alone can't pass an EU CRA audit.

SCA Scanner Output
CVE-2026-3391 → #4410 detection only
nested 4 layers deep no governance
MTTR 55 days avg no SLA clock
exported to scan.json not a record
What an EU CRA audit checks
Intake → triage → remediation → disclosure, with named owners
Every transitive dependency, governed and current
A 24-hour early-warning clock with owned SLAs
Machine-readable SBOMs, continuously updated + attested provenance

Detection isn’t the same as a fix

Your scanner flags a vulnerability and opens a ticket, and that's where its job ends. Under the EU CRA, you’re required to have an auditable end-to-end process for intake, triage, remediation, and disclosure, with defined SLA timing and named operational owners at every stage.

Most vulnerabilities aren’t in code you chose

A flagged CVE is usually nested four layers down, in a dependency your developers never directly chose. 64% of production open source lives in these transitive layers, and manually tracing, updating, and re-testing them costs hours of developer time, with standard tooling offering no way to govern it.

You can’t report what you can’t see

The EU CRA's 24-hour early warning clock starts at disclosure, whether or not you know if the vulnerability affects you. Many teams can't respond in that timeframe, because they don't have a current inventory of every component, direct and transitive, running in production.

There’s a missing paper trail

Scanner records aren't an audit record. EU CRA demands machine-readable SBOMs, continuously updated, backed by attested provenance. Without automated governance, developer time meant for shipping gets spent writing compliance logs and chasing manifests by hand instead.

Take the EU CRA Engineering Readiness Assessment

EU CRA reads like a compliance problem, but it's actually a resourcing problem, with a due date.

Maintaining a governed OSS inventory, current SBOM coverage, and audit-ready remediation records isn't a one-time project. It's an ongoing engineering obligation. The only real question is whether your team builds that capability or buys it, and whether that call gets made through purposeful design before September 11, or by default after.

Build Staff it yourself

A roadmap with no end point

FTE-weeks per quarter 010203040 38 Q3Q4Q1Q2Q3Q4
Invest Adopt the capability

One integration, then steady state

FTE-weeks per quarter 010203040 1× integrate 4 Q3Q4Q1Q2Q3Q4

The ActiveState Curated Catalog turns "build" into a capability you don't have to staff

Every component ships with cryptographic attestation and verifiable provenance, with no debate over whether you can prove what's running.

SBOM coverage is automated and current across every package and transitive dependency.

Packages, and their full dependency trees, are built to SLSA Level 3 standards across your language ecosystems.

Remediation runs on a 5 business day SLA for Critical CVEs, a timeline your team can plan around.

Only validated components enter your toolchain in the first place, through the tools your developers and their AI coding agents already use.

The Curated Catalog feeds vetted, policy-compliant packages through the artifact repo, CI/CD pipeline, and AI assistants into every downstream service — each marked secure

What's running in your product is no longer a question. It's a verified record.

Talk to an expert Take the EU CRA Engineering Readiness Assessment