Webinar
Why Your EOL Open Source Stack Is a Compliance Liability, Not Tech Debt
A practical session for engineering, security, and compliance leaders navigating CRA, NIS2, DORA, and more.
Date:
Sep 17, 2026
Time
11:00 AM EST
Duration:
45 min
The Regulation Driving the Session
The EU Cyber Resilience Act.
The CRA sets security obligations for any product with digital elements placed on the EU market, and it treats the software supply chain as in scope. Reporting duties for actively exploited vulnerabilities apply from September 2026, with the full set of obligations from December 2027. An end-of-life component that no longer receives upstream patches stops being a backlog item at that point and becomes a control gap that has to be answered in a conformity assessment. We'll work through what that means for teams whose migration windows extend past the deadlines.
Also Covered
- NIS2 — supply-chain security and incident reporting duties for essential and important entities.
- DORA — ICT risk management and third-party oversight for EU financial entities.
- US federal — how the same EOL evidence requests are read under FedRAMP and NIST 800-53.
What You'll Learn
- Where EOL becomes a compliance finding
- What the deadlines require in practice
- Evidence that satisfies a reviewer
- Options when the window is short
Who Should Attend
This webinar is built for IT leaders, compliance and security professionals, and senior engineering leaders who want a clearer picture of how their organization's open source stack may be affected by upcoming regulations and security requirements.
CAN'T MAKE IT LIVE?
Register anyway — we'll send the full recording and our companion whitepaper, “The Developer's Guide to Security Compliance”, to everyone who signs up.
Register for Webinar
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

