Vulnerability Compliance Hubs — BOD 26-04, FedRAMP, EU CRA, EU AI Act
Compliance Hubs

The regulatory map for AI-era vulnerability management.

Four regimes now govern how organizations must find, prioritize, and report vulnerabilities — two already in force with hard deadlines this year, one arriving in 2027, and one that's voluntary but increasingly consequential. Each hub below is a practitioner-grade guide maintained against primary sources.

LAST REVIEWED: SEPTEMBER 10, 2026
Need help meeting these deadlines?
Get matched with a vetted partner.

Tell us what you're trying to solve and we'll connect you with a vetted partner.

Get Matched with a Partner →
In force · United States
CISA BOD 26-04

Four-variable risk model, 72-hour critical tier, forensic triage requirement. Agency policy deadline August 7, 2026.

Enter the BOD 26-04 hub →
In force September 11, 2026 · European Union
EU Cyber Resilience Act (Article 14)

A hard legal mandate, not voluntary coordination: manufacturers of products with digital elements sold into the EU must report actively exploited vulnerabilities within 24 hours. Applies to non-EU companies too.

Enter the CRA hub →
Mandatory December 7, 2026
FedRAMP VDR/VER

Certification revocation after March 7, 2027. Exceeds BOD 26-04 in key respects, including the "Assume It's Automatable" standard.

Enter the FedRAMP hub →
High-risk obligations December 2, 2027
EU AI Act

Deferred to December 2, 2027 (Annex III) and August 2, 2028 (embedded systems) by the Digital Omnibus, formally adopted June 2026. The deferral is preparation runway, not a reprieve: conformity assessment requirements remain extensive.

Enter the EU AI Act hub →