The Cyber Resilience Act (CRA) for U.S.-Based Companies
Join CRA expert Valerie Aurora for practical guidance on how U.S.-based companies can determine CRA scope, meet 2026 reporting obligations, and prepare for 2027 CE marking.
The EU Cyber Resilience Act (CRA) isn't just a European concern. If your company sells software or connected products into the EU market, the CRA applies to you, no matter where you're headquartered. This includes the many businesses based in the United States that sell products in the EU.
The CRA's vulnerability and incident reporting obligations took effect in September 2026, and full compliance will be required by December 2027. This means organizations must juggle active processes for discovering and reporting vulnerabilities with preparation for the obligations that take effect next year. The starting point for many companies, however, is figuring out whether the CRA applies to your product(s) in the first place.
We invite you to join CRA expert (and contributor to the development of multiple CRA standards) Valerie Aurora for a webinar that will cover practical next steps for U.S.-based organizations. We'll discuss how to determine whether your products are in scope, what the 24-hour, 72-hour, and final vulnerability reports require, how to navigate open questions around CSIRTs and authorized representatives, and how to build the SBOM and vulnerability-handling foundations you'll need before 2027.
You'll learn:
- How to determine whether your products fall under the CRA and which product classification and conformity assessment path applies.
- What the September 2026 reporting obligations require, including what counts as an actively exploited vulnerability and a severe security incident.
- How U.S. companies should approach choosing a CSIRT, appointing authorized representatives, and registering for the Single Reporting Platform.
- What manufacturers owe the open source projects they depend on, and how CRA responsibilities differ for commercial companies and non-profit OSS stewards.
- How to build the SBOM, documentation, and continuous vulnerability-monitoring practices you'll need for 2027 CE marking.
Register for This Webinar
Fill out the form below to secure your spot in this webinar.
Wednesday, November 18, 20269:00 AM PT / 12:00 PM ET
About FOSSA
FOSSA is a leading application security and compliance platform that specializes in helping engineering teams deliver trusted software.
FOSSA enables companies to prioritize real vulnerabilities in their open source software with comprehensive SCA (software composition analysis) capabilities, while also making it possible for organizations to automate compliance reporting and SBOM (software bill of materials) lifecycle management to meet customer and regulatory requirements.
Founded in 2015, FOSSA is trusted by thousands of global organizations, has been downloaded nearly two million times, and has conducted nearly 100 million scans of open-source software.
Related Webinars
Register for This Webinar
Fill out the form below to secure your spot in this webinar.
Wednesday, November 18, 20269:00 AM PT / 12:00 PM ET


