The Cyber Resilience Act (CRA) makes no exceptions—security is the key to entering the supply chain
The Cyber Resilience Act has been in effect since December 2024, and unlike NIS2, there are no exemptions for small businesses. Anyone who manufactures, imports, or sells products with digital components must demonstrate security in the future—through security-by-design, a software bill of materials, and 24-hour reporting deadlines.
Reporting requirements take effect on September 11, 2026; the CRA will be fully in force as of December 11, 2027, with fines of up to 15 million euros . This makes cybersecurity the ticket to entering the supply chain—and the question of where highly sensitive security documents are located becomes a matter of sovereignty.
The regulation that hardly anyone is aware of—and that affects almost everyone
NIS2 and the EU AI Act dominate the headlines. The Cyber Resilience Act operates more quietly but has a broader reach: It doesn’t ask about the industry, but rather about a single characteristic of the product—can it exchange data? As soon as a product can have a direct or indirect connection to devices, networks, APIs, or cloud services, it falls under the CRA.
The key difference from NIS2: There are no size-based exemptions whatsoever. A five-person software company is subject to the same basic obligations as a large corporation, and the responsibility is personal—management is liable. In Germany, the BSI monitors the market and specifies the requirements.
Criterion: “Product with digital elements”
The CRA covers networked hardware such as routers, sensors, and industrial control systems; traditional software products such as operating systems and apps; individually marketed components such as firmware and modules; and cloud functions required for a networked product. Manufacturers, importers, distributors, and private-label providers are subject to these obligations.
An important clarification: Pure SaaS services initially fall under NIS2. However, as soon as software is made available as a product on the EU market or is part of a connected product as remote data processing, it becomes subject to the CRA. The only exceptions are sectors with their own regulatory frameworks, such as medical devices, motor vehicles, or aviation; non-commercial open-source software is exempt.
What specifically needs to be done starting in September 2026
The CRA requires four things that entail significant effort in day-to-day operations:
- Security by Design: Security must be built into the product from the very first architectural decision—including authentication, data flow control, and multi-tenancy.
- Software Bill of Materials (SBOM): a complete list of components comprising in-house development, open-source libraries, cloud services, and third-party components. Without this transparency, there is no compliance.
- Vulnerability management with strict reporting deadlines: Initial report of an actively exploited vulnerability within 24 hours, follow-up report after 72 hours, and a final report 14 days after a fix becomes available.
- Conformity and CE marking: for new products.
The timeline is tight: effective as of December 10, 2024; reporting requirements begin September 11, 2026; full applicability for new products begins December 11, 2027. Existing products are exempt from the full requirements, but the reporting obligations still apply. The price of negligence: up to 15 million euros or 2.5 percent of global annual revenue.
The catch: Compliance generates precisely the data that needs to be protected
This is where things get uncomfortable for many companies. Everything the CRA requires generates highly sensitive data: source code, the complete supply chain SBOM, detailed vulnerability reports, and incident documentation. These very documents serve as a roadmap to the company’s own attack surface.
Storing and processing this data on U.S. hyperscalers solves one compliance problem while creating a new one: sovereignty and CLOUD Act risks. To make matters worse, government support is scarce—only about 1.28 million euros per year are earmarked for CRA assistance to SMEs, while the EU’s SECURE program provides 16.5 million euros for risk analyses and security assessments. Those who wait lose time, which is in short supply.
From Cost Factor to Ticket to the Market
There is a second way of looking at this, and from a business perspective, it’s the more exciting one. CRA compliance is becoming a currency in the supply chain: clients demand verifiable security standards before making a purchase. Those who provide proof become preferred partners; those who fail to do so lose contracts.
The CRA isn’t alone in this. It intertwines with NIS2, the GDPR, and the EU AI Act—the entire regulatory stack is moving in the same direction: verifiable, auditable, and sovereign infrastructure. Once this foundation is properly established, it fulfills multiple requirements at once, rather than requiring a separate project for each regulation.
Sovereign Infrastructure as the Foundation for CRA
For companies in regulated industries, a sovereign, German infrastructure serves as an ideal foundation on which to fulfill CRA obligations without creating new risks. SecureCloud provides this layer: sovereign storage and collaboration for source code, SBOMs, and vulnerability documentation; audit-proof processes for tight reporting deadlines; and, with SecureKI, an agent-based AI workspace that assists in creating and maintaining SBOMs, technical documentation, and draft reports—all on European infrastructure, without sensitive security data ever leaving this sovereign foundation.
Interessiert Sie die souveräne Cloud?
Hier geht's zur kostenlosen Testphase
Sebastian Deck
Sebastian Deck is Chief Marketing Officer (CMO) at SecureCloud and is responsible for brand strategy, communications and marketing. He has many years of experience in building and leading international marketing teams in consulting, fintech and technology companies. At SecureCloud, he drives brand positioning, thought leadership and lead generation. He also manages go-to-market initiatives and campaigns to position SecureCloud as a leading provider of cyber security and secure cloud services.