About this talk
This talk, presented by Daniel Thompson-Yvetot from CrabNebula Ltd and Tauri, examines how open source tooling can enhance compliance operations within public sector contexts, specifically under the Cyber Resilience Act (CRA). The session discusses the challenges faced by market surveillance authorities (MSAs), including limited resources and the need for effective vulnerability management and conformity assessment. It introduces a prototype tool that automates vulnerability triage using data from sources like NVD, OSV, and EUVD, enabling non-specialist operators to perform preliminary assessments efficiently. The speaker emphasizes the importance of scalable solutions and interoperability among regulatory bodies to facilitate consistent compliance enforcement across the EU.