> Markdown version of [/events/world-congress-2026-europe/sessions/1279-reporting-active](https://www.wearedevelopers.com/events/world-congress-2026-europe/sessions/1279-reporting-active). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Reporting Active Exploits in 24 Hours: Are You Ready for the CRA? - **Date:** Friday, Jul 10, 2026 - **Time:** 11:40–12:10 (30 min) - **Room:** Stage 8 - powered by Red Hat - **Event:** World Congress 2026 Europe ## Recording [Watch recording](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Description Most organisations’ vulnerability management processes are not built for the CRA’s mandatory 24‑hour reporting of actively exploited vulnerabilities, let alone the required 72‑hour follow‑up submissions. This session highlights the gaps that will matter most when these obligations take effect—from real‑time detection and exploitation confirmation to dependency visibility, evidence capture, and integration across AppSec, SecOps, and product teams. Using practical examples, we explore where current processes fail and what must be modernised: automation, intelligence feeds, cross‑team workflows, and documentation readiness. Attendees will leave with concrete steps to rebuild their AppSec operations for speed, accuracy, and CRA compliance before regulatory pressure makes the choice for them. ## Speaker ### [Matthew Brady](https://www.wearedevelopers.com/@matthew-brady) Sales Engineering Manager at Black Duck ## Related talks at this congress - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/events/world-congress-2026-europe/sessions/1178-one-pipeline-three) — Marcus Ross - [Defending the Modern Supply Chain: Hands-On Vulnerability Remediation](https://www.wearedevelopers.com/events/world-congress-2026-europe/sessions/995-defending-the-modern) — Boy Baukema, Patrick Feige - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/events/world-congress-2026-europe/sessions/1442-checkmate-5-real) — Jasmin Azemović - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/events/world-congress-2026-europe/sessions/1280-the-developer) — Marcus Wermuth