Upcoming Webinar Closing the Risk Gap: Power and Proof with Checkmarx Fusion Register Today
Press Release Checkmarx Fusion: Hybrid Scanning Delivers the Most Complete Vulnerability Detection Available Read Now
Gartner® Checkmarx Named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security Get the Report
Outlook Report The Future of Application Security in the Era of AI Download Now
Latest Innovations
Checkmarx for Developers
Partners
Blog
Research
EU Security Regulation

ECB AI Security Mandate

Assess your readiness, close critical gaps, and build a credible, audit-ready action plan by the October 31st deadline.

The Risk Driving the Mandate

96%
of organizations have AI embedded in their applications
49%
of production code is now AI-generated
75%
of organizations knowingly deploy vulnerable code
3.4x
more risk carried by AI-generated code

What Is the ECB Mandate?

On July 7, 2026, the European Central Bank (ECB) instructed 110 European financial institutions
to submit comprehensive action plans by October 31st outlining how they
will address AI-enabled cybersecurity threats.

Building on DORA, the mandate requires banks to demonstrate how they’ll strengthen
cybersecurity controls as AI makes it easier for attackers to find,
exploit, and introduce vulnerabilities.

Each action plan must define clear measures, owners, resources, and timelines.

What Your Action Plan
Needs to Cover

Protect the attack surface:

Secure exposed assets, cloud environments, access controls, and aging infrastructure.

Accelerate vulnerability management:

Prioritize and fix critical vulnerabilities faster.

Strengthen detection and resilience:

Improve monitoring, response, recovery, and crisis management.

Govern software and AI risk:

Maintain oversight of third parties, open source, AI assets, and ownership.

Checkmarx Supports Your ECB Action Plan

ECB requirement

Accelerate patching velocity

Checkmarx capability

Triage and Remediation Assist identifies findings requiring immediate action and delivers merge-ready fixes directly into pull requests.

ECB requirement

Govern third-party and open-source risk

Checkmarx capability

SCA and Malicious Package Protection continuously discover dependencies and identify malicious packages before they appear in the NVD.

ECB requirement

Inventory AI assets

Checkmarx capability

AI Supply Chain Security and AI-BOM provide an inventory of the models, MCPs, tools, and agents embedded in software.

ECB requirement

Demonstrate active risk management

Checkmarx capability

ASPM and SBOM unify risk across code, open source, APIs, containers, and infrastructure, while tracking remediation progress.

Start Building Your ECB Action Plan

ECB Mandate Solution Brief

See how Checkmarx One maps the ECB’s requirements to practical actions across vulnerability management, software supply chain risk, AI governance, and reporting.

Read Now

AI AppSec Program Maturity Assessment (AI APMA)

Benchmark your program against ECB expectations and find your AI security gaps before the October 31st deadline.

Learn More

The Future of Application Security Report

See the AI-driven risk data behind the ECB’s mandate, and why regulators are moving on it now.

Learn More

Checkmarx Fusion

Fuses deterministic scanning with frontier AI models to catch the vulnerabilities the ECB is asking banks to close.

Learn More
Get ECB Ready

The October 31, 2026
Deadline Is Approaching

Assess your readiness, identify critical gaps, and take the next steps toward a credible response.

A Gartner® Magic Quadrant Leader™
A Forrester Wave Leader™
SOC 2 Type II Certified