Workshop 2026
Save the date
November 9-13, 2025
qSkills GmbH & Co. KG, Suedwestpark 65, 90449 Nuremberg, Germany
Vulnerabilities in hardware and software are omnipresent. After all, all software and hardware is flawed beyond a certain level of complexity, and such flaws can potentially lead to security-relevant vulnerabilities that are exploited accordingly. Such security-relevant vulnerabilities are like open wounds. They need to be taken care of. To do this, it must be known where the “wound” is located, what kind of “wound” it is and how it can be healed or at least initially treated as quickly as possible.
The digital solution for all these issues is CSAF (https://csaf.io): The Common Security Advisory Framework (CSAF) is a standardized and open-source framework for the communication and automated distribution of machine-processable vulnerability and mitigation information, so-called security advisories or security information.
CSAF significantly reduces the manual effort required to search for security information and to determine whether products are affected or not. It allows manufacturers, users, operators and the administration to automatically retrieve information on individual vulnerabilities and to determine whether they are affected. Being not affected can also be communicated in a scalable manner (Vulnerability Exploitability eXchange (VEX) as a profile in CSAF). In the course of an increasingly networked and complex world, the number of security-relevant vulnerabilities will grow significantly and modern vulnerability management using CSAF documents will become indispensable. OASIS is organizing a whole week long training on the topic of CSAF from 09.11.2026 to 13.11.2026.
The workshops will be held in English and in presence.
The registration for all workshop will open soon at qSkills’ website.
The workshops will be held in conjunction with the CSAF Community Days.

Prerequisites for Participation in the Workshop
- The workshops are aimed at the target group: manufacturers, CERTs, research institutions, security researchers
- Joy of learning new things
- Interest in Security Advisories
- Very good knowledge of English, as the entire workshop will be held in English
- Mandatory basic knowledge of Command Line commands (for the majority of the tools used in the workshops)