World Congress 2026 Europe

Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?

July 10, 2026 11:40 – 12:10 · 30 min Stage 8 - powered by Red Hat

What this session covers

Most organisations’ vulnerability management processes are not built for the CRA’s mandatory 24‑hour reporting of actively exploited vulnerabilities, let alone the required 72‑hour follow‑up submissions. This session highlights the gaps that will matter most when these obligations take effect—from real‑time detection and exploitation confirmation to dependency visibility, evidence capture, and integration across AppSec, SecOps, and product teams. Using practical examples, we explore where current processes fail and what must be modernised: automation, intelligence feeds, cross‑team workflows, and documentation readiness. Attendees will leave with concrete steps to rebuild their AppSec operations for speed, accuracy, and CRA compliance before regulatory pressure makes the choice for them.

Related talks at this congress

Open session

World Congress 2026 Europe

July 9, 2026 · 16:50–17:20

Airstream 1

One Pipeline, Three Regulator - SBOM Compliance for the Developer

Marcus Ross

Platform Engineering & Process Framework at Die Techniker

Marcus Ross
Open session

World Congress 2026 Europe

July 9, 2026 · 10:30–12:30

Room M3 (18 Seats)

Defending the Modern Supply Chain: Hands-On Vulnerability Remediation

Boy Baukema, Patrick Feige

Boy Baukema
Patrick Feige
Open session

World Congress 2026 Europe

July 9, 2026 · 15:30–16:00

Airstream 1

Checkmate: 5 Real Incidents That Can End a Software Company

Jasmin Azemović

CISO| Associate Professor | Microsoft MVP

Jasmin Azemović
Open session

World Congress 2026 Europe

July 10, 2026 · 11:40–12:10

Stage 10 - powered by TikTok

The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most

Marcus Wermuth

VP of R&D at Safety Cybersecurity

Marcus Wermuth
All sessions at this congress