Dev.to
7/18/2026

The EU Cyber Resilience Act Has an EOL Problem — and the Deadline Isn't the One You Think
Short summary
The EU Cyber Resilience Act's vulnerability and incident reporting obligations begin September 11, 2026 — over a year before the commonly cited December 2027 main obligations deadline. Products shipping with end-of-life components (e.g., Debian 10, AngularJS, OpenSSL 3.0) cannot meet the CRA's security-update requirements, turning tech debt into a compliance gap with fines up to €15M or 2.5% of global turnover. Teams need automated component inventory, live lifecycle tracking, risk-ranked remediation, and extended-support bridges starting now to avoid missing the runway.
- •CRA vulnerability reporting begins Sept 11, 2026 — not Dec 2027 as widely assumed
- •EOL dependencies in shipped products create unfixable compliance gaps under the CRA
- •OpenSSL 3.0 loses upstream support 4 days before the CRA reporting deadline begins
Generated with AI, which can make mistakes.
Is this a good recommendation for you?


