12.08.2025
Blog
Regulatory
Manufacturing

The Cyber Resilience Act – What digital product manufacturers need to know now

With the Cyber Resilience Act (CRA), adopted on 23 October 2024, the EU is introducing a binding framework for the security of digital products. Companies in the manufacturing sector that offer connected devices or products with digital elements are therefore facing far-reaching changes – and an opportunity to future-proof their digital resilience.

Heike Abels
Corporate Communications Officer

The Cyber Resilience Act, with its reporting requirements for vulnerabilities and security incidents, comes into force on 11 September 2026. Whilst this may sound like something for the future, it requires concrete preparations to be made today: security processes, lifecycle management and transparent product information must be established and put into operation now. Companies that act now will not only ensure compliance but also secure a decisive competitive edge.

The digital ingredients list: a requirement, not an option

In future, digital products must be documented in the same way as foodstuffs: with a complete list of all components they contain – the so-called Software Bill of Materials (SBOM). Added to this are instructions for use and a clear indication of when security updates will cease – effectively the ‘digital best-before date’.

Business operators such as manufacturers, importers, distributors and all those who develop software for the product are obliged to provide security updates throughout the entire product lifecycle and to operate an effective vulnerability management system. Products with digital elements for which, for example, the software components contained are not disclosed, do not fulfil the obligation to provide security updates – and the companies responsible risk severe penalties.

How can the complex requirements of the CRA be implemented efficiently and sustainably?

Implementing the CRA initially represents a major change for organisations; this should be managed and monitored through the organisation’s Information Security Management System (ISMS) and integrated into the continuous improvement process over the coming years.

This requires the establishment of a resilient ISMS within the organisation that integrates the CRA’s requirements, monitors them and implements appropriate measures to secure the products. These must be regularly reviewed through a continuous improvement process (CIP) to identify risks, vulnerabilities and necessary adjustments due to environmental factors.

A systematic approach using Enterprise Architecture Management

To actively manage the digital complexity of security measures for products and the necessary IT infrastructure, we recommend the use of Enterprise Architecture Management (EAM).

EAM provides a systematic approach to documenting, analysing and purposefully developing IT and business architectures along defined perspectives (e.g. applications, data, technologies, processes).

Particularly in the context of the Cyber Resilience Act, EAM enables:

  • the identification of affected digital products and components, as well as the assessment of their architectural and security-related maturity
  • the traceability of software versions and dependencies (e.g. SBOM)
  • a structured mapping of security and update obligations throughout the lifecycle
  • as well as integration into existing governance and reporting processes

In short:

  • An ISMS is necessary to implement the CRA’s regulatory requirements sustainably within the organisation.
  • EAM provides the methodological foundation not only to meet regulatory requirements such as the CRA, but also to integrate them strategically into the development of digital architecture.
  • With its comprehensive cyber security expertise, Materna supports organisations in integrating the requirements of the CRA into their ISMS to ensure that minimum cyber security requirements are met throughout the entire lifecycle of digital products.
  • Our EAM and cyber security experts help organisations build transparency – not only for the CRA, but also in conjunction with other EU regulations such as the NIS2 Directive, the EU Data Act and the EU AI Act.

Think holistically, reap multiple benefits

Many of the CRA’s requirements are not new – sectors such as the automotive and medical technology industries have already overcome comparable challenges. Their recipe for success? A holistic IT architecture that integrates regulatory requirements rather than treating them in isolation. This is precisely where Materna comes in: together with our clients, we develop a unified governance, risk and security strategy that responds flexibly to new regulations and safeguards companies in the long term.

Security by Design – getting it right from the start

An integrated ISMS takes regulatory requirements such as the CRA into account across the entire organisation. This encompasses business processes, corporate values, staff and products. This enables the CRA’s requirements to be implemented and demonstrated holistically within the organisation.

Through Enterprise Architecture Management, vulnerabilities are identified at an early stage, measures are systematically documented and IT components are assessed in context – exactly as required by the CRA.

Whether it involves connected products, embedded devices, software solutions or cloud-based components, the integration of ITSM, CMDB and BPM systems creates transparency regarding digital product architectures and their interdependencies. This not only meets the CRA’s requirements but also specifically strengthens the security and compliance strategy.

Take action now: greater resilience, less risk

With the Cyber Resilience Act coming into force, product security becomes a corporate obligation – and an opportunity to actively shape the digital future. Through an integrated ISMS and the development of transparent architectures and intelligent lifecycle management, organisations lay the foundations for greater security, lower risk and sustainable competitiveness.

Want to find out more? Download our latest white paper on the subject here.

Further information on cyber security

Further information on enterprise architecture management

Heike Abels
Corporate Communications Officer

Heike Abels works at Materna as a Corporate Communications Officer. She is responsible for the editorial content of various formats used for external communications. Her work focuses on Cross Market Services, which includes Enterprise Service Management, Customer Service and Cyber Security.

Related articles

Short News
Europe
Sustainability
Data & AI
28.08.2026
Green AI is not a romantic notion

Anyone wishing to operate AI in a sustainable, autonomous and responsible manner must take a holistic view of computing power, energy, governance, cybersecurity and resilience.

Read more
Blog
Verwaltung Digital
Sustainability
Public Sector
25.11.2025
Sustainability through IT: How digital services strengthen the state, society and the environment

In the sustainability sector, there is often talk of the ‘twin transformation’ – digitalisation and sustainability as a shared challenge. But how…

Read more
Blog
Sustainability
06.08.2024
‘Forest and Timber 4.0’ data room: sustainability redefined through AI

Sustainability is a concern for everyone. Materna is committed to developing and implementing sustainable solutions. The ‘CO2For-IT’ project…

Read more
Blog
Sustainability
10.04.2024
Future-proof data infrastructure: the key to effective ESG management

Given the growing importance of the European Sustainability Reporting Standards (ESRS), companies face the complex task of presenting their…

Read more
Blog
Sustainability
23.11.2023
ESG management: A digital and sustainable path to the future

To achieve long-term success, it is now essential for businesses to address their own environmental and social responsibilities. Find out how…

Read more
Blog
Sustainability
17.01.2023
From digital to sustainable transformation: ensuring the industry’s future viability

When it comes to future-proofing in industry, companies are faced with complex scenarios. Innovation and sustainable practices are essential.…

Read more
Blog
Sustainability
10.01.2023
From digital to sustainable transformation: strengthening resilience in industrial companies

How can industrial companies increase their resilience in a dynamic competitive environment and against a backdrop of global and macroeconomic…

Read more
Blog
Corporate
Sustainability
29.03.2022
Materna joins the UN Global Compact

The UN Global Compact is the world’s largest initiative for sustainable and responsible business practices. Materna has joined the initiative and…

Read more