Boosted by @welcome@friends.deko.cloud
#introduction
I work on software supply-chain evidence, and I have one argument I would like to be wrong about.
The CRA's two dates get planned in the wrong order. Reporting an exploited vulnerability within 24 hours starts 11 September 2026. The machine-readable SBOM is only required from 11 December 2027 — fifteen months after the clock starts.
On a 24-hour clock the first question is not how to word the notification. It is which of your services ship the component.
#CRA #SBOM