The 'Vulnerability Response Capability' Required Beyond SBOMs On September 11, 2026, reporting obligations under the EU Cyber Resilience Act (CRA) will commence. As of the time of this webinar, approximately 90 days remain. Many companies are rushing to prepare their Software Bill of Materials (SBOM).

However, the CRA demands more than just the submission of an SBOM. It requires: - Publishing and operating vulnerability reporting channels - Swift assessment and notification of exploited vulnerabilities - Continuous update capabilities - An organizational structure that makes these processes 'repeatable'

What is being scrutinized is not just whether you are aware of vulnerabilities, but whether you are in a state where you can continuously respond to them. The CRA essentially visualizes the quality fundamentally expected of software products. Today, there is a demand for a new organizational competence: 'vulnerability response capability.'

Stalling Due to Lack of Visibility and Assessment Many teams are facing significant hurdles: - Inability to fully identify where vulnerabilities exist - Difficulty in prioritizing findings - Inability to make release decisions - Vulnerability management relying on individual specialists rather than organizational processes

These are not merely technical or tooling issues but structural problems defined by an inability to grasp, assess, and execute. The industry is entering a domain where traditional diagnostic-centric approaches are no longer sufficient.

Rethinking Operations and Organizational Design Beyond SBOMs This webinar redefines CRA compliance through the lens of 'product quality capable of responding to changing threat environments even after shipment.' By dissecting why vulnerability management stalls and why organizational processes fail, the session explains the concepts of 'assessment' and 'operations' necessary beyond SBOMs.

- Target Audience: Manufacturers, embedded device providers, and software vendors with products for the European market. - Key Takeaways: Integrated risk management, setting priorities, and building sustainable operational frameworks.

Organizer: Asterisk Research Inc. Co-organizer: Majisemi Co., Ltd.

FACT BOX

  • Source: PR TIMES
  • Category: Event
  • Products / services: SBOM