The 24-hour CRA deadline is changing software supply chain visibility
The EU Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities within 24 hours starting September 11. FossID's Aaron Branson argues that SBOM confidence, not just SBOM possession, is the real bottleneck.