It’s been a long time in the making, but the Cyber Resilience Act (CRA) is finally here. And it couldn’t have come a moment sooner. As AI empowers threat actors to probe for new weaknesses in digital products, and exploit recently published flaws at ever greater speed, there’s an urgent need for vendors to improve cyber-risk management. Now they have a regulatory mandate to force their hand.

But the businesses best able to adapt to the new rules, and use compliance as a driver of better operational security, will be those that take a continuous approach to compliance. They will also focus on putting in place structured, repeatable governance processes before something bad happens, not once they are plunged into the chaos of incident response.

What Happens Now?

The CRA is a worthwhile effort to improve the security and reliability of connected technology and make it easier for buyers to find high-quality products via a kite mark scheme. It applies to all manufacturers of hardware and software products with a digital element (PDEs) which sell into the EU, plus importers and distributors. Penalties of up to €15m (£12.9m) or 2.5% of annual turnover mean non-compliance is not an option.

The new reporting rules, effective from September 11, 2026, demand that in-scope entities:

  • Identify and document actively exploited vulnerabilities in PDEs (and any relevant backend/cloud services)
  • Identify any severe incidents that have an impact on the security of a PDE
  • Notify government authorities, customers, and suppliers/partners of these vulnerabilities or severe incidents within 24 hours of becoming aware (initial early warning)
  • Issue a main notification within 72 hours
  • Produce a final report 14 days after a patch or mitigating measure has been applied

By 11 December 2027, in-scope organisations will also be expected to remediate any vulnerabilities (taking into account the risks they pose) “without delay”.

The rules come as regulators on both sides of the Atlantic respond to growing concerns about AI-powered vulnerability research and exploit development. The window of opportunity that network defenders have to apply vendor updates in, before systems are exploited, has collapsed. At the same time, AI is finding an order of magnitude more flaws in software. Microsoft’s September Patch Tuesday posted a record 974 CVEs.

In the US back in June, CISA issued Binding Operational Directive 26-04: Prioritizing Security Updates Based on Risk. It requires federal agencies to improve prioritization of updates according to the risk they pose and accelerate patching timelines for those deemed high risk. That will depend on technical impact, whether they’ve been exploited, and whether systems are internet reachable, among other things.

Getting Your House in Order

To ensure they meet the CRA’s requirements, organisations will have to act now, according to Veeam Software EMEA field CISO, Andre Troskie.

“They need to have the correct telemetry, component visibility, and crucially, a decision process that can move in hours, not days,” he tells IO (formerly ISMS.online). “That means establishing clear ownership and escalation routes for assessing whether an issue is reportable, establishing when they became aware of it, understanding its impact, and producing the evidence needed as part of the notification process.”

Codific CEO and OWASP SAMM contributor, Aram Hovsepyan, argues that while most large vendors should find CRA compliance a relatively easy lift, less mature companies may come up short. A structured and repeatable risk management approach will be key to meeting these new reporting obligations, and other activities mentioned in the CRA, he tells IO.

“I strongly believe that eventually this is going to be the bottom line. To get repeatable reporting in place you will have to move towards a more proactive approach to security assurance as opposed to the reactive way we were doing things for quite a while,” Hovsepyan continues.

“With the reporting obligations now in force, organisations will get the opportunity to set up a more proactive approach that will help them immensely in the long run.”

Vincent Lomba, chief product security officer at Alcatel-Lucent, argues that organisations have no time to waste. “Considering how severe the financial penalty is under the CRA, there has never been a more significant time to ensure organisations have structured, repeatable governance processes in place before an incident happens,” he tells IO.

“Because adapting long-standing organisational processes takes years, not weeks, leaders cannot afford to wait for a crisis to test their readiness. True cyber resilience demands proactive, structured governance that embeds security into the company’s daily DNA long before a crisis could appear.”

The direction of travel must be continuous oversight of the sort advocated by ISO 27001 and other best practice standards, Lomba continues. “Continuous assurance is essential to maintain compliance across rapidly changing software,” he argues.

“The rise of AI has triggered a 50-fold increase in vulnerabilities being exploited by bad actors. Because CRA obligations mandate ‘security by design’ across the entire product lifecycle static, periodic compliance audits are no longer fit for purpose. Tight deadlines maintain this accountability.”

Reaping the Rewards

Such an approach will boost remediation efforts and reduce compliance risk. But it also offers business benefits beyond the avoidance of CRA fines.

“Establishing structured reporting enables organisations to prioritise cybersecurity as a formal financial business case based on risk management which can then be presented to the board to highlight its importance,” concludes Lomba.

“It also helps organisations gain a competitive edge in European markets; to win customer deals and avoid the friction facing non-compliant vendors.”

In this way, compliance evolves from its traditional role as a business blocker to one of growth enabler. And the cybersecurity and GRC teams finally emerge as strategic functions dedicated to unlocking new opportunities.

Expand Your Knowledge

Blog: Everything You Need To Know About the Cyber Resilience Act

Podcast: Phishing for Trouble S2 E8: What The Regulators Want

Blog: Beyond The Breach: Why The Response Is Now The Story