## March Office Hours: Building Your CRA Vulnerability Management Plan

## Transcript

00:00 Welcome and Agenda  
01:01 What Is the CRA  
01:45 Scope Fines and Classification  
03:59 Key Dates and Core Duties  
04:53 SBOM and Reporting Workflow  
06:33 DefectDojo CRA Readiness  
06:59 Locations Framework for SBOMs  
08:32 Reporting Feature and End to End Flow  
10:03 Getting Data In and Triage  
11:22 Deduplication and Enrichment  
14:16 Remediation SLAs and Verification  
15:19 Practical Next Steps to Comply  
17:28 New PSIRT Engine Preview  
20:14 Q&A and Closing

Hi everyone. Happy Wednesday. Thanks for joining us today. My name is Greg Anderson. I'm the CEO and creator of DefectDojo.  
And we've been getting a lot of questions around the CRA and so we wanted to put a webinar together to talk to the community about what it means in preparing this presentation. We have tried to look specifically at the letter of the law. There is a ton of blogs out around the CRA and so we wanted to make sure that everything we were pulling from was directly from the actual regulations and annexes that have been published.

### What Is the CRA
And so, starting with what is the CRA? There's this new Cyber Resiliency Act in Europe and we've seen a ton of regulations in cybersecurity come and go. There have been some regulations in the past that people have been concerned about, and then they didn't turn into fruitful things that changed our industry. We believe that CRA will be different because it's heavily inspired by GDPR. GDPR is one of the most successful regulations in changing behavior. When it comes to the CRA, we expect to see similar impacts that happened with GDPR.

### Scope Fines and Classification
The concern today is primarily in Europe. GDPR's notoriety drove the world to wake up to this regulation. Key takeaways about fines, penalties, and scope are that they are very similar to GDPR; they're meant to be scary and high to drive enforcement. This applies to any company doing business in Europe. Self-classification allows companies to decide how they report under this regulation.

### Key Dates and Core Duties
Reporting obligations start this year, with full compliance required later. There will likely be widespread panic globally around enforcement starting December. Key duties include maintaining a comprehensive SBOM in specific formats and adhering to timelines for vulnerability management.

### SBOM and Reporting Workflow
The regulation mandates specific formats such as Cyclone DX. Reporting obligations entail notifying authorities 24 hours after discovery and submitting a full report within 14 days following specific steps. Penalties for non-compliance are serious, comparable to GDPR enforceability.

### DefectDojo CRA Readiness
DefectDojo is preparing for compliance, needing to implement key enhancements in SBO management. The locations framework is undergoing significant changes to provide a global view across all assets.

### Locations Framework for SBOMs
The existing model of tracking vulnerable components is being replaced by a framework called locations, allowing a more comprehensive view of vulnerabilities across all assets.

### Reporting Feature and End to End Flow
New reporting access management features are planned for implementation shortly.

### Getting Data In and Triage
DefectDojo makes data import flexible. Various options are available for users to bring in data efficiently, such as API connectors, push options, and direct UI submissions.

### Deduplication and Enrichment
The Dojo platform includes deduplication mechanisms to ensure accurate scan comparisons. Additionally, threat intel updates every 24 hours to inform users about vulnerabilities in the system.

### Remediation SLAs and Verification
Custom SLAs should be created according to CRA regulations for asset management. Auto-remediation capabilities are being researched to enhance user experiences within the platform.

### Practical Next Steps to Comply
Begin by inventorying products to establish compliance protocols around the CRA. Define SLAs that align with the requirements and continue monitoring compliance dashboards for progress.

### New PSIRT Engine Preview
A new PSIRT engine is under development aimed at enhancing management tools for vulnerability insights from threat feeds. This feature is expected to improve the efficacy of security teams and provide better management for their risks.

### Q&A Closing
I appreciate the time taken to engage with this content today and welcome any further questions regarding the platform or participation in our community.
