With the CRA September 2026 deadline approaching for mandatory vulnerability reporting, balena co-sponsored a deep-dive study published by The Linux Foundation and the Open Source Security Foundation (OpenSSF), detailed in the 2026 CRA Awareness and Readiness Report. The findings reveal a wide gap between impending legal requirements and how companies manage open-source dependencies, with 66% of industry respondents remaining entirely unfamiliar with the regulation.