The Cyber Resilience Act has been in effect since December 2024, and unlike NIS2, there are no exemptions for small businesses. Anyone who manufactures, imports, or sells products with digital components must demonstrate security in the future—through security-by-design, a software bill of materials, and 24-hour reporting deadlines.
Reporting requirements take effect on September 11, 2026; the CRA will be fully in force as of December 11, 2027, with fines of up to 15 million euros . This makes cybersecurity the ticket to entering the supply chain—and the question of where highly sensitive security documents are located becomes a matter of sovereignty.
The regulation that hardly anyone is aware of—and that affects almost everyone
NIS2 and the EU AI Act dominate the headlines. The Cyber Resilience Act operates more quietly but has a broader reach: It doesn’t ask about the industry, but rather about a single characteristic of the product—can it exchange data? As soon as a product can have a direct or indirect connection to devices, networks, APIs, or cloud services, it falls under the CRA.
The key difference from NIS2: There are no size-based exemptions whatsoever. A five-person software company is subject to the same basic obligations as a large corporation, and the responsibility is personal—management is liable. In Germany, the BSI monitors the market and specifies the requirements.
Criterion: “Product with digital elements”
The CRA covers networked hardware such as routers, sensors, and industrial control systems; traditional software products such as operating systems and apps; individually marketed components such as firmware and modules; and cloud functions required for a networked product. Manufacturers, importers, distributors, and private-label providers are subject to these obligations.
An important clarification: Pure SaaS services initially fall under NIS2. However, as soon as software is made available as a product on the EU market or is part of a connected product as remote data processing, it becomes subject to the CRA. The only exceptions are sectors with their own regulatory frameworks, such as medical devices, motor vehicles, or aviation; non-commercial open-source software is exempt.
What specifically needs to be done starting in September 2026
The CRA requires four things that entail significant effort in day-to-day operations:
The timeline is tight: effective as of December 10, 2024; reporting requirements begin September 11, 2026; full applicability for new products begins December 11, 2027. Existing products are exempt from the full requirements, but the reporting obligations still apply. The price of negligence: up to 15 million euros or 2.5 percent of global annual revenue.
The catch: Compliance generates precisely the data that needs to be protected
This is where things get uncomfortable for many companies. Everything the CRA requires generates highly sensitive data: source code, the complete supply chain SBOM, detailed vulnerability reports, and incident documentation. These very documents serve as a roadmap to the company’s own attack surface.
Storing and processing this data on U.S. hyperscalers solves one compliance problem while creating a new one: sovereignty and CLOUD Act risks. To make matters worse, government support is scarce—only about 1.28 million euros per year are earmarked for CRA assistance to SMEs, while the EU’s SECURE program provides 16.5 million euros for risk analyses and security assessments. Those who wait lose time, which is in short supply.
From Cost Factor to Ticket to the Market
There is a second way of looking at this, and from a business perspective, it’s the more exciting one. CRA compliance is becoming a currency in the supply chain: clients demand verifiable security standards before making a purchase. Those who provide proof become preferred partners; those who fail to do so lose contracts.
The CRA isn’t alone in this. It intertwines with NIS2, the GDPR, and the EU AI Act—the entire regulatory stack is moving in the same direction: verifiable, auditable, and sovereign infrastructure. Once this foundation is properly established, it fulfills multiple requirements at once, rather than requiring a separate project for each regulation.
Sovereign Infrastructure as the Foundation for CRA
For companies in regulated industries, a sovereign, German infrastructure serves as an ideal foundation on which to fulfill CRA obligations without creating new risks. SecureCloud provides this layer: sovereign storage and collaboration for source code, SBOMs, and vulnerability documentation; audit-proof processes for tight reporting deadlines; and, with SecureKI, an agent-based AI workspace that assists in creating and maintaining SBOMs, technical documentation, and draft reports—all on European infrastructure, without sensitive security data ever leaving this sovereign foundation.