Security1 distinct publisher3 min readPublished
EU Cyber Resilience Act enforcement starts in September with personal liability for security leaders written in, according to JFrog, so the lag between an auditor's request and the proof now has a named owner.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Evidence latency is the one number here you can time with a calendar. A control either has an artifact sitting next to it or it does not, and the interval between the request and the proof arriving is measurable. JFrog puts that interval above one week for 48% of the organizations it surveyed [2], drawn from a population where 59% said they had full provenance visibility into their software supply chains [1]. The same respondents gave both answers.
The denominator is what stops either figure from being quotable to the decimal. JFrog's post gives no sample size, no fielding dates, and no statement of whether the 48% is a subset of the 59% or the full respondent pool [12]. If it is a subset, the week-plus group is roughly 28% of all respondents rather than 48% (0.48 x 0.59 = 0.283) [13]. Both readings point the same way, and neither would survive an argument in front of an auditor; the figures were published by JFrog inside its own product announcement [16].
The CRA claim carries the stakes and the thinnest sourcing. JFrog dates enforcement to this September [4] and says the regulation is the first to write personal liability for security leaders into its text [5]. The post does not say which of the CRA's obligations begin in September, and it does not cite the article that creates the liability [15]. That sentence is worth checking against the regulation before anyone budgets against it.
The mechanism underneath the lag is mundane. Take the CRA line requiring vendors to follow all secure coding practices appropriate to development languages and environments [6]. Turning that legal language into something enforceable is work, not a given: someone has to decide which pipeline stage enforces it, write the rule in Rego, the policy language behind Open Policy Agent, test it, and scope it to the right applications [7]. Every new framework restarts that work from scratch, and JFrog argues point-in-time checks produce the feeling of compliance without the substance [14].
Its answer, shipped this week at swampUP 2026, is a catalog of NIST SSDF and EU CRA controls pre-mapped to policy rules in AppTrust, which launched a year earlier at the same event [8][9]. Uncovered controls are flagged, and controls already satisfied by running AppTrust show as covered by default [10]. JFrog says the coverage score tracks production because governance and artifacts share one system of record [17]. NIST SSDF already gates US federal procurement, so the mapping work has a buyer either way [3].
None of this points to anything exploitable, with no CVE, no actor, and no patch window behind it. What changed is the size of the problem: the consequence of a slow answer, and the volume of code now needing one. JFrog says AI agents are now writing code, reviewing pull requests, and pushing changes at rates compliance review was not built for, without putting a figure on it [11].</body_markdown> </invoke>
Ranked by verification strength, evidence, and original report placement.
JFrog says 59% of organizations claim full provenance visibility into their software supply chains.
In JFrog's survey, 48% needed more than a week to produce proof of compliance when auditors asked for it.
The EU Cyber Resilience Act comes into enforcement this September, according to JFrog.
The CRA includes a requirement to "follow all secure coding practices appropriate to development languages and environments".
Turning such a control into enforcement requires policy written in Rego, the policy language behind Open Policy Agent, then tested and scoped to the right applications.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
Cloudsmith's cooldown policies make delay a control, and that makes it your decision1 distinct publisher
build
Fabricated SQLite CVEs cleared NVD, CISA ADP and Red Hat before anyone ran the code1 distinct publisher
security
Two Artifactory flaws poisoned metadata, not artifacts, and that was enough to break a shared cache1 distinct publisher
security
An ASD-endorsed assessor ran the entire JFrog platform against the ISM at Protected level1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Two percentages, one author, no methodology
The 59% and the 48% carry this entire story, and both surface for the first time in the same JFrog post that sells the fix — no sample size, no fielding window, and no answer to the question of whether the slow-to-prove 48% sits inside the 59% or across everyone surveyed. The regulatory scaffolding is asserted the same way: CRA enforcement in September and a first-ever personal liability provision, neither tied to an article of the regulation. What is genuinely well evidenced is narrow and mundane — what JFrog shipped, and what it says the feature does.
Announced on stage, unobserved in the field
The record contains exactly one event: JFrog saying, at its own conference, that the frameworks shipped. There is no user, no design partner, no early-access cohort, no count of applications under a framework, and no coverage figure telling an AppSec lead how much of SSDF or CRA the catalog actually reaches. The predecessor product's year in market is mentioned as background but never quantified either, so the only thing measurable is availability.
Deadline pressure runs ahead of the proof
Three of the most persuasive lines are also the least supported: that the CRA is the first regulation to make security leaders personally liable, that AI agents are pushing change at volumes no review can absorb — with no number attached anywhere — and that the coverage score always reflects production because governance shares a system of record with the artifacts. Each is plausible; none is shown. Against that, the concrete product claims are modest and specific, which keeps this short of the worst kind of overstatement.
The statistic and the remedy share a byline
JFrog measured the problem, published the measurement, named the deadline, and shipped the product that answers all three — in one post, in one week, at its own conference. The word 'we' appears where the launch is recounted. That alignment is not concealed and does not make the numbers false, but a reader should notice that the 48% audit lag exists in public only as the setup for a compliance catalog, and that CISO personal liability is the mechanism converting that lag into a purchase.
Certain what this is, uncertain whether it works
Little ambiguity attaches to reading this story: a vendor announcement, dated, with its provenance on its face and its gaps visible without any digging. That supports firm judgments about sourcing and incentives. It supports almost none about substance — whether pre-mapped controls survive a real audit, how much of each framework they cover, or whether the September timing is as sharp as stated will only become knowable when someone other than JFrog writes about it.