Cyber Resilience Act (CRA): What manufacturers of digital products need to know now

A router that stops receiving security updates after two years. A networked machine control system where no one can say for sure which open-source libraries are inside. Such cases were long an annoyance, but not a legal violation. That is now changing: With the Cyber Resilience Act (CRA), the EU has established binding cybersecurity requirements for connected products for the first time. For manufacturers, the first major operational compliance date was September 11, 2026. 

What is the Cyber Resilience Act?  

The Cyber Resilience Act (CRA) is an EU regulation that introduces uniform cybersecurity requirements for so-called “products with digital elements”. This refers to hardware and software that are directly or indirectly connected to other devices or networks. The regulation was published in the Official Journal of the EU on November 20, 2024, and entered into force on December 10, 2024.  

The underlying concept: Cybersecurity should no longer be something that is retrofitted after an incident, but a feature that is considered across the entire product lifecycle – from concept through development and production to the usage phase. As an EU regulation, the CRA applies directly in all member states; no national implementation is required.  

Thus, the CRA aligns with a logic familiar from product safety law: Anyone placing a product on the European market must be able to prove that it meets certain requirements. What is new is that cybersecurity is now explicitly included.  

Who is affected by the CRA?  

 Manufacturers, importers, and distributors of products with digital elements placed on the EU market are affected. The scope of application is intentionally broad, ranging from consumer devices like smartwatches and baby monitors to industrial components, IoT sensors, firewalls, and routers. Pure software products also fall under its scope.  

The CRA differentiates based on risk: In addition to the default category, there are “important” and “critical” products with digital elements, for which stricter conformity assessment requirements apply. For manufacturers, this means first of all: It is worth assessing your own portfolio early on to determine which products fall under the scope of application at all and which category they belong to.  

Another point that is easily overlooked is also important: The reporting obligations from September 2026 apply not only to products newly placed on the market after this date. They also cover products that have already been in the field for years. For many companies, this means having to deal with an installed base whose software versions are not consistently documented.  

The supply chain adds another layer of complexity. Today, hardly any connected product consists solely of proprietary code – open-source libraries, purchased modules, and firmware from suppliers are the rule. Responsibility toward the market remains with the manufacturer, regardless of where a vulnerability originates.  

Timeline and Deadlines  

The CRA becomes effective in stages. Here are the dates you should have on your calendar:  

The reporting deadlines are the part that experience shows puts organizations under pressure first. 24 hours is not a time frame in which a reporting chain can still be improvised – the processes, responsibilities, and contact channels must be established beforehand.  

The Key Obligations for Manufacturers  

In terms of content, the requirements of the CRA can be boiled down to a few key points:  

Risk assessment over the lifecycle. Manufacturers must assess, document, and implement appropriate cybersecurity risk protection measures – not just once, but continuously across design, development, production, and usage.  

Software Bill of Materials (SBOM). A machine-readable bill of materials of the contained software components must be maintained for every affected product, at least down to the level of direct dependencies. Common formats are SPDX and CycloneDX. The SBOM does not need to be published, but it belongs in the technical documentation and must be presented to market surveillance authorities upon request. And it must stay up to date: Every update potentially changes the software version.  

Vulnerability and patch management. Security updates must be provided over an appropriate support period. This requires manufacturers to know which software version and configuration were delivered with a particular product and which versions are currently installed in the field. 

Technical documentation and CE marking. From December 2027, CE marking is a prerequisite for market access. It is based on documentation that makes conformity verifiable.  

The sanctions are substantial: Non-compliance can be penalized with fines of up to 15 million euros or 2.5 percent of total worldwide annual turnover.  

What Companies Should Do Now  

Companies that have not yet completed their reporting readiness should treat this as an immediate operational priority. Four steps are a sensible starting point:  

  1. Clarify applicability. Which products fall within the scope of application and which risk class applies?  
  1. Set up reporting processes. The 24-hour deadline starting in September 2026 is the immediate hurdle. Who reports, to whom, via which channel – and who decides whether a vulnerability is “actively exploited”?  
  1. Build SBOM capabilities. This should not be understood as a one-off project, but as part of the development and release process.  
  1. Clarify responsibilities. The CRA affects security, product development, quality assurance, and compliance simultaneously. Without clear assignment, the task gets lost between departments. 

Rather than running these activities as a separate compliance project alongside product development, companies should embed them into existing development and release processes. Requirements that live only in a separate proof folder quickly become outdated – those anchored in the release process remain up to date.  

Where a Consistent Product Database Helps  

Most CRA requirements ultimately lead back to the same question: Can you state – even five years after delivery – which components a particular product contains, which requirements applied to it, and which software version and configuration were delivered?  

This is precisely where a PLM platform comes in. CONTACT Elements maps the product lifecycle end-to-end and links requirements, components, documents, and revision statuses with one another. This traceability is not CRA compliance in itself – but it is the foundation on which SBOM maintenance, technical documentation, and proof management for authorities can be organized in a practical manner, rather than scrambling to gather them from scattered sources in an emergency.  

If you are considering how to integrate CRA requirements into your existing development processes, please feel free to contact us.  

Conclusion  

The Cyber Resilience Act shifts cybersecurity from a voluntary quality issue to a prerequisite for market access. The deadlines in September 2026 and December 2027 may seem comfortable at first glance, but they affect processes that cannot be built overnight – in particular, reporting chains and a reliable documentation of your own software inventory. The best time to start is well before the deadline. 

ISO 27001 Certification: security as a standard for our cloud products

Digitalization is shaping our lives and workplaces like never before. With this evolution comes an increased responsibility to protect data effectively and ensure stable service delivery. Information security is no longer a “should” but an absolute “must.”

As a provider of industrial software solutions from the cloud, quality, security, and reliability are our top priorities. We are delighted to announce our successful ISO 27001 certification by Datenschutz Cert. This confirms our commitment to providing products that meet the highest security standards and effectively protect data.

More security, efficiency, and sustainability with automation

Our goal was clear from the beginning: to meet security and stability requirements with innovative technologies. We rely heavily on automation and Infrastructure as Code (IaC) to achieve this. These measures enable us to implement security mechanisms effectively and integrate them seamlessly into our development and operating processes.

One crucial aspect of our preparations was to take climate risks into account. Events like extreme weather pose potential threats to IT infrastructures. In response, we developed solutions that minimize risks while enhancing efficiency – such as monitoring tools and automated scaling. These technologies reduce our carbon footprint and help to ensure a high level of security and sustainability.

Security culture as a success factor

Information security is more than just meeting standards—it is an integral part of our corporate culture. Principles such as high availability, automation, and the use of a single source of truth define how we work and foster a structured approach to tackling complex challenges. A standout aspect is the contribution of our team. Regular training and a high level of security awareness ensure that information security is not just seen as a task for IT, but is practiced throughout the entire company. This holistic mindset was a cornerstone of our journey to achieving ISO 27001 certification.

Our automation strategies further illustrate how we combine efficiency with security. By standardizing processes, we reduce human error while laying the foundation for continuous improvement.

Added value for customers and partners

For our customers, certification means one thing above all: trust. ISO 27001 certification is an internationally recognized seal of quality and confirms that we adhere to the highest security standards. This not only enhances the reliability of our cloud products but also assures our customers that their data is in safe hands.

Our partners also benefit significantly from this certification. Standardized processes and clearly defined security requirements make collaboration more seamless, boost efficiency, and establish a foundation of trust for future projects. It is a crucial competitive advantage, especially in a dynamic environment like the cloud industry.

Our vision for the future

ISO 27001 certification is not an endpoint for us but a milestone in our ongoing journey to continuously enhance our security measures. For instance, we plan to make our monitoring systems even more robust, enabling us to detect potential risks more quickly and address them more effectively. The digital landscape is constantly changing – we are ready to face these challenges and ensure the security of our customers, partners, and their data.

How will the Data Act affect the industry?

Successful digital transformation requires access to data and its intelligent use. The EU has therefore defined a regulation that is intended to strengthen the European data market: the Data Act. Companies from traditional industries must adapt to it as soon as possible.

What is the Data Act?

The “Regulation on harmonised rules on fair access to and use of data” (Data Act) is a directive of the European Union that defines regulations regarding data access and use. It aims to create a fair, transparent framework for the exchange and use of data within the EU, thereby promoting innovation and increasing the competitiveness of European companies on the global data market.

The Data Act is a key component of the EU’s digital strategy. It was approved by the European Council on November 27, 2023 and came into force on January 11, 2024. Following a 20-month transition period, it is to be converted into directly applicable EU-wide law from September 12, 2025.

What is the motivation?

Data is a key resource in the digital economy. However, due to a lack of guidelines, legal requirements, and standards, a large part of the data generated remains unused, especially in industry.

Furthermore, we are currently observing a strong imbalance on the market: data is mostly owned by a small group of large companies. Compared to SMEs and start-ups, this gives them a considerable competitive advantage, which is reflected, for example, in one-sided contracts regarding data access and use.

To counteract this, the EU has developed the Data Act. It aims to democratize the market and create a balanced, fair data ecosystem. To this end, the EU has defined a legal framework ensuring that users of networked products or connected services can promptly access the generated data.

The objectives of the Data Act in a nutshell:

  • Clear rules for the use and exchange of data
  • Transparency and fairness within the data market
  • Protection of personal data
  • Secure data processing
  • Promotion of data-driven innovations
  • Increased competitiveness of EU companies

Who is affected by the Data Act?

The Data Act addresses companies, organizations, and individuals who

  • bring connected products to the market,
  • offer connected services,
  • as a data owner, share generated data with third parties,
  • receive data from data owners,
  • as a public institution, request data owners to share data, or
  • offer data processing services.

Persons who participate in data rooms and providers of applications that include smart contracts are also affected. Persons whose trade, business, or profession involves the implementation of smart contracts for others in connection with the execution of an agreement must also comply with the Data Act.

Which tasks result from the Data Act?

The Data Act imposes numerous new obligations on the industry. These include:

Making data accessible: Providers must ensure that users of connected devices or connected services have access to the data they generate.

Ensuring portability: The Data Act demands mechanisms that enable users to easily and securely transfer their data to third parties. This includes the development of standards and interfaces for data exchange.

Ensuring transparency and fairness: Companies must be transparent about what data they collect, how they use it, and who has access to it.

Ensuring data protection: The processing and disclosure of data must comply with applicable data protection laws (e.g., the GDPR).

Enabling cooperation with authorities: In many cases, it is necessary to pass on data to public institutions. This requires clear processes and responsibilities.

Data Act vs. Data Governance Act

The Data Act is not the only pillar of the European data strategy. It also includes the Data Governance Act (DGA), an existing regulation that defines processes and structures for the exchange of data between individuals, companies, and public institutions. In contrast, the Data Act focuses more on promoting the digital economy. It regulates which players are allowed to use the generated data under which conditions.

What are the consequences of violating the Data Act?

Unfortunately, it is not yet possible to predict how these aspects will be structured in detail. The EU regulation has not yet been transposed into German law. It therefore remains to be seen what obligations will arise in Germany and which supervisory authorities will oversee implementation.

However, one thing is clear: violations of the Data Act will result in fines, similar to the GDPR. There is also a risk that companies will be sued for damages by other market players if they fail to meet the requirements. Furthermore, it is possible that products and services that do not comply with the Data Act may no longer be sold in the EU.

Does the Data Act only create new duties?

The EU regulation does not only entail obligations. It opens up many new opportunities for SMEs in particular. If data is available to all market players in interoperable formats, this facilitates the implementation of innovative, data-based services, such as predictive maintenance.

This is precisely what the democratization of the data market aims to achieve. It gives companies more control over the way they handle their data and creates rules that facilitate data transfer. Both data owners and users will benefit from this.

Processes that are complex and time-consuming today will be accelerated. For example, the regulation provides clear rules for contract management. Cloud or edge providers, for instance, must contractually and technologically ensure that customers can transfer their data as easily as possible when they switch systems.

The industry will also benefit from increasing competition. For example, machine manufacturers who want to enable their products for the Internet of Things can currently only turn to a few providers for this purpose. The Data Act opens up this restricted circle. This not only increases the quality of products and services but also leads to lower prices.

According to a representative survey by the digital association Bitkom, Germany’s economy is currently divided on the Data Act. 49 percent of the 603 companies surveyed across all economic sectors see the new EU regulation as an opportunity for their business. On the other hand, 40 percent of respondents consider the Data Act to be a risk.

What is the best approach for companies?

Companies dealing with the Data Act quickly come up against complex issues: How do they ensure that the data interfaces of their machines, systems, and products are accessible to third parties? What impact does the sharing of data have on their business model? What opportunities does this present (e.g., new services and offers)?

Many of these questions are currently still unclear, making it difficult to prepare for the EU regulation. However, it is advisable to put the topic on the strategic agenda and seek an exchange with associations and other companies. This dialog helps assess the impact of the Data Act on your business.

Summary

With the Data Act, the EU wants to equip the European data market for international competition. The regulation promotes a secure, efficient flow of data and creates a framework that facilitates data exchange and use. This results in new business obligations, but also fairer market conditions.

How the Data Act will be implemented in Germany remains to be seen. Manufacturing companies should nevertheless get to grips with the contents as soon as possible. It is a complex set of rules that influences topics ranging from technological infrastructure to processes and contract design. Companies affected must adequately prepare themselves.

Further information

Handling data is becoming increasingly important for a company’s success. A reliable security architecture is essential, especially for cloud users. In our guide “IT security for companies”, you can read about the requirements for this and the factors you should consider when selecting software providers.