Heike Abels
Referentin für Unternehmenskommunikation

The Cyber Resilience Act, with its reporting requirements for vulnerabilities and security incidents, comes into force on 11 September 2026. Whilst this may sound like something for the future, it requires concrete preparations to be made today: security processes, lifecycle management and transparent product information must be established and put into operation now. Companies that act now will not only ensure compliance but also secure a decisive competitive edge.

The digital ingredients list: a requirement, not an option

In future, digital products must be documented in the same way as foodstuffs: with a complete list of all components they contain – the so-called Software Bill of Materials (SBOM). Added to this are instructions for use and a clear indication of when security updates will cease – effectively the ‘digital best-before date’.

Business operators such as manufacturers, importers, distributors and all those who develop software for the product are obliged to provide security updates throughout the entire product lifecycle and to operate an effective vulnerability management system. Products with digital elements for which, for example, the software components contained are not disclosed, do not fulfil the obligation to provide security updates – and the companies responsible risk severe penalties.

How can the complex requirements of the CRA be implemented efficiently and sustainably?

Implementing the CRA initially represents a major change for organisations; this should be managed and monitored through the organisation’s Information Security Management System (ISMS) and integrated into the continuous improvement process over the coming years.

This requires the establishment of a resilient ISMS within the organisation that integrates the CRA’s requirements, monitors them and implements appropriate measures to secure the products. These must be regularly reviewed through a continuous improvement process (CIP) to identify risks, vulnerabilities and necessary adjustments due to environmental factors.

A systematic approach using Enterprise Architecture Management

To actively manage the digital complexity of security measures for products and the necessary IT infrastructure, we recommend the use of Enterprise Architecture Management (EAM).

EAM provides a systematic approach to documenting, analysing and purposefully developing IT and business architectures along defined perspectives (e.g. applications, data, technologies, processes).

Particularly in the context of the Cyber Resilience Act, EAM enables:

  • the identification of affected digital products and components, as well as the assessment of their architectural and security-related maturity
  • the traceability of software versions and dependencies (e.g. SBOM)
  • a structured mapping of security and update obligations throughout the lifecycle
  • as well as integration into existing governance and reporting processes

In short:

  • An ISMS is necessary to implement the CRA’s regulatory requirements sustainably within the organisation.
  • EAM provides the methodological foundation not only to meet regulatory requirements such as the CRA, but also to integrate them strategically into the development of digital architecture.
  • With its comprehensive cyber security expertise, Materna supports organisations in integrating the requirements of the CRA into their ISMS to ensure that minimum cyber security requirements are met throughout the entire lifecycle of digital products.
  • Our EAM and cyber security experts help organisations build transparency – not only for the CRA, but also in conjunction with other EU regulations such as the NIS2 Directive, the EU Data Act and the EU AI Act.

Think holistically, reap multiple benefits

Many of the CRA’s requirements are not new – sectors such as the automotive and medical technology industries have already overcome comparable challenges. Their recipe for success? A holistic IT architecture that integrates regulatory requirements rather than treating them in isolation. This is precisely where Materna comes in: together with our clients, we develop a unified governance, risk and security strategy that responds flexibly to new regulations and safeguards companies in the long term.

Security by Design – getting it right from the start

An integrated ISMS takes regulatory requirements such as the CRA into account across the entire organisation. This encompasses business processes, corporate values, staff and products. This enables the CRA’s requirements to be implemented and demonstrated holistically within the organisation.

Through Enterprise Architecture Management, vulnerabilities are identified at an early stage, measures are systematically documented and IT components are assessed in context – exactly as required by the CRA.

Whether it involves connected products, embedded devices, software solutions or cloud-based components, the integration of ITSM, CMDB and BPM systems creates transparency regarding digital product architectures and their interdependencies. This not only meets the CRA’s requirements but also specifically strengthens the security and compliance strategy.

Take action now: greater resilience, less risk

With the Cyber Resilience Act coming into force, product security becomes a corporate obligation – and an opportunity to actively shape the digital future. Through an integrated ISMS and the development of transparent architectures and intelligent lifecycle management, organisations lay the foundations for greater security, lower risk and sustainable competitiveness.

Want to find out more? Download our latest white paper on the subject here.

Further information on cyber security

Further information on enterprise architecture management

Heike Abels
Referentin für Unternehmenskommunikation

Heike Abels arbeitet bei Materna als Referentin für Unternehmenskommunikation. Sie betreut redaktionell verschiedene Formate für die externe Kommunikation. Thematischer Schwerpunkt ist der Bereich Cross Market Services. Dazu zählen Enterprise Service Management, Customer Service und Cyber Security.

Related articles

Press
Dortmund/Berlin
02.09.2026
Materna and deepset are strengthening cutting-edge AI made in Germany

Materna and deepset are combining their expertise to advance the confident use of artificial intelligence in the public sector and in regulated industries. Their joint offering combines Materna’s experience in digitizing complex administrative and IT…

Read more
Short News
Corporate
Cyber Security
31.07.2026
From Rising Star to Leader: Materna has been recognised as a Leader in Strategic Security Services in the ISG Provider Lens™ Cyber Security – Services and Solutions 2026

ISG has recognised Materna as a leading provider of cyber security consultancy in Germany.

Read more
Press
Dortmund
08.07.2026
agineo is gearing up for the next phase of the ServiceNow market

The market for enterprise platforms such as ServiceNow solutions is changing. Today, companies expect more than just the successful roll-out of a platform. They are looking for partners who can operate platforms securely, continuously develop them…

Read more
Press
Corporate
Data & AI
Public Sector
Dortmund
17.06.2026
SPARK, the AI for public authorities: Materna group helps public authorities speed up approval processes

With the launch of SPARK Workflow, public authorities now have access to a centralised AI-powered tool to process planning and approval procedures more quickly. As a member of the consortium responsible for the project, the Materna Group is…

Read more
Press
Corporate
Dortmund
11.06.2026
Lünendonk List 2026: Materna climbs to eighth place

A major success for the Dortmund-based IT service provider Materna. Lünendonk’s analysts have now ranked the long-established company among the top 10 leading IT consulting and systems integration firms in Germany.

Read more
Press
Europe
Corporate
Dortmund
02.06.2026
Materna opens a site in Brussels

The Materna Group has established its own subsidiary, Materna Belgium B.V., in the Belgian capital. With this move, Materna is responding to the EU’s growing operational responsibility in running complex digital systems.

Read more
Press
Dortmund
21.05.2026
SmartLivingNEXT: Data room links housing, energy and health

At the closing conference, Materna will present key findings from the SmartLivingNEXT research programme and invite companies, start-ups and the housing sector to play an active role in further developing the data ecosystem.

Read more
Press
Dortmund
19.05.2026
Materna opens a new site in Koblenz dedicated to defence and digital sovereignty

Materna Information & Communications SE officially opened its new premises in Koblenz on 18 May 2026. This move enables the company to further expand its collaboration with clients from the Bundeswehr and the public sector. The aim is to provide…

Read more
Short News
Public Sector
30.04.2026
Materna & TrustNXT: Strategic technology partnership for digital trust protection

Digital content is now a key component of critical processes – which makes its authenticity all the more important.

That is why Materna and TrustNXT…

Read more
Press
14.04.2026
Materna and Neo4j enter into a strategic partnership for graph intelligence and explainable AI

Materna Information & Communications SE and Neo4j, provider of the graph intelligence platform of the same name, have entered into a strategic partnership. Through this collaboration, Materna is expanding its portfolio to include solutions for the…

Read more