Prepare for the Cyber Resilien... Note
GitLab

Prepare for the Cyber Resilience Act's 24-hour reporting deadline

The EU's Cyber Resilience Act (CRA) mandates that businesses selling software in the EU must report actively exploited vulnerabilities within 24 hours of awareness. This new law aims to ensure digital products are secure by design and remain supported against evolving threats. The primary challenge for compliance lies in rapidly detecting when a vulnerability in shipped software is being actively exploited. Continuous detection, an engineering solution, is crucial for meeting the strict 24-hour reporting deadline.GitLab offers capabilities to help businesses address these challenges and answer key questions regarding their software supply chain security. These include identifying current exploitation of shipped components and finding all affected products and repositories. The platform's activity logs and webhooks help document when vulnerabilities were identified, crucial for reporting timelines. GitLab's features also enable tracking the shipping of fixes for vulnerabilities.Many aspects of CRA compliance, such as vulnerability detection and timestamping, are already integrated into the GitLab platform. Future CRA requirements, set for December 2027, will focus on preventing risky packages from entering the supply chain. GitLab is developing preventive policies to block harmful packages before they reach the build stage. Businesses are encouraged to test GitLab's capabilities to assess their readiness for the CRA's reporting obligations. Existing customers can evaluate their current component's vulnerability status within GitLab.