Evidence IT

EU Cyber Resilience Act to Impose New Software Security Obligations

The EU Cyber Resilience Act (CRA) is introducing significant new cybersecurity obligations for software and connected digital products sold in the European Union. The regulation is designed to make cybersecurity a fundamental part of how digital products are designed, developed, maintained and supported throughout their lifecycle.

For software manufacturers, developers and businesses operating in or supplying the European market, the changes represent a shift towards greater accountability for vulnerabilities and security risks.

The Cyber Resilience Act entered into force on 10 December 2024, with its main obligations due to apply from 11 December 2027. However, important reporting requirements are already in effect from 11 September 2026, meaning organisations need to begin preparing now.

What is the EU Cyber Resilience Act?

The Cyber Resilience Act establishes mandatory cybersecurity requirements for products with digital elements. This includes a broad range of software and hardware capable of connecting directly or indirectly to devices or networks.

Products covered can include applications, computer programmes, Internet of Things devices, smart technology and other connected products. The legislation applies to manufacturers placing these products on the EU market, including organisations based outside the European Union.

The central principle is security by design, rather than treating cybersecurity as an issue that can be addressed after a product has been released, manufacturers must consider security throughout planning, development, production, delivery and maintenance.

New software security obligations

One of the most important changes is the requirement for manufacturers to conduct cybersecurity risk assessments and implement measures to address identified vulnerabilities.

Under the CRA, manufacturers must ensure that vulnerabilities are handled effectively throughout a product’s defined support period. Security updates must address relevant vulnerabilities, while users must also receive clear information about secure installation, configuration and operation.

Manufacturers will also need to establish and communicate the expected support period for products; the end date, including the month and year, must be clearly provided to customers.

This could have significant implications for software development teams, secure coding, vulnerability management, dependency monitoring, security testing and incident response will increasingly need to form part of standard software development and product management processes.

Vulnerability reporting is already required

Although the majority of the CRA applies from December 2027, manufacturers already have new reporting responsibilities.

From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents affecting products with digital elements. An initial warning must generally be submitted within 24 hours of becoming aware of an actively exploited vulnerability or severe incident, followed by a more detailed notification within 72 hours.

The European Union Agency for Cybersecurity (ENISA) has established the CRA Single Reporting Platform, allowing manufacturers to submit the required information through a single system rather than separately notifying multiple authorities.

These deadlines mean organisations need effective vulnerability detection, escalation and incident response procedures. Without reliable processes, it may be difficult to identify, investigate and report incidents within the required timeframe.

What does the CRA mean for businesses?

The Cyber Resilience Act could affect businesses well beyond their cybersecurity teams. Software developers, product managers, compliance professionals, procurement teams and senior management may all have responsibilities connected to compliance.

Organisations should consider reviewing their current security practices, including:

  • Software development and secure coding procedures
  • Vulnerability identification and remediation
  • Third party and open source software dependencies
  • Security testing and risk assessments
  • Incident detection and reporting processes
  • Product support periods and security update policies
  • Customer security documentation
  • Cybersecurity responsibilities throughout the supply chain


The European Commission published practical CRA guidance in July 2026 to help manufacturers, developers and businesses understand requirements including product scope, support periods, substantial modifications, risk assessments and reporting.

Why cybersecurity compliance matters

The CRA represents a broader move towards making manufacturers responsible for the security of digital products throughout their lifecycle.

For businesses supplying software to European customers, compliance should not be viewed solely as a regulatory exercise. Maintaining accurate vulnerability records, investigating security incidents and deploying timely security updates can also strengthen an organisation’s wider cyber risk management strategy.

Importantly, the CRA applies across the product lifecycle rather than focusing exclusively on security at the point of sale. This means organisations need processes capable of continuing to identify and manage cybersecurity risks after products reach customers.

Preparing for the Cyber Resilience Act

With the principal CRA obligations becoming applicable on 11 December 2027, businesses have a defined period in which to assess their readiness, reporting obligations, however, are already applicable from September 2026.

Businesses should begin by identifying which products and software fall within the regulation, understanding their role in the supply chain and documenting existing cybersecurity controls. A gap assessment can then help identify areas requiring investment or procedural changes.

Cybersecurity and digital forensic expertise can also support organisations in investigating vulnerabilities, understanding security incidents, preserving relevant evidence and improving incident response processes.

For businesses developing or supplying digital products in Europe, the EU Cyber Resilience Act is set to make software security a much more visible and accountable part of product development. Preparing early can help organisations understand their obligations and establish the technical and governance processes needed before the main requirements take effect.

Source: https://insight.scmagazineuk.com/eu-cyber-resilience-act-to-impose-new-software-security-obligations

Eu,Cyber,Resilience,Act,-,Cra,,Representing,European,Cybersecurity,Regulations

CONTACT US FOR Digital Risk Management

You can be absolutely sure of a confidential, trustworthy and discreet service at all times, Evidence IT delivers results.

Contact us