The Cyber Resilience Act, with its reporting requirements for vulnerabilities and security incidents, comes into force on 11 September 2026. Whilst this may sound like something for the future, it requires concrete preparations to be made today: security processes, lifecycle management and transparent product information must be established and put into operation now. Companies that act now will not only ensure compliance but also secure a decisive competitive edge.
The digital ingredients list: a requirement, not an option
In future, digital products must be documented in the same way as foodstuffs: with a complete list of all components they contain – the so-called Software Bill of Materials (SBOM). Added to this are instructions for use and a clear indication of when security updates will cease – effectively the ‘digital best-before date’.
Business operators such as manufacturers, importers, distributors and all those who develop software for the product are obliged to provide security updates throughout the entire product lifecycle and to operate an effective vulnerability management system. Products with digital elements for which, for example, the software components contained are not disclosed, do not fulfil the obligation to provide security updates – and the companies responsible risk severe penalties.
How can the complex requirements of the CRA be implemented efficiently and sustainably?
Implementing the CRA initially represents a major change for organisations; this should be managed and monitored through the organisation’s Information Security Management System (ISMS) and integrated into the continuous improvement process over the coming years.
This requires the establishment of a resilient ISMS within the organisation that integrates the CRA’s requirements, monitors them and implements appropriate measures to secure the products. These must be regularly reviewed through a continuous improvement process (CIP) to identify risks, vulnerabilities and necessary adjustments due to environmental factors.
A systematic approach using Enterprise Architecture Management
To actively manage the digital complexity of security measures for products and the necessary IT infrastructure, we recommend the use of Enterprise Architecture Management (EAM).
EAM provides a systematic approach to documenting, analysing and purposefully developing IT and business architectures along defined perspectives (e.g. applications, data, technologies, processes).
Particularly in the context of the Cyber Resilience Act, EAM enables:
- the identification of affected digital products and components, as well as the assessment of their architectural and security-related maturity
- the traceability of software versions and dependencies (e.g. SBOM)
- a structured mapping of security and update obligations throughout the lifecycle
- as well as integration into existing governance and reporting processes
In short:
- An ISMS is necessary to implement the CRA’s regulatory requirements sustainably within the organisation.
- EAM provides the methodological foundation not only to meet regulatory requirements such as the CRA, but also to integrate them strategically into the development of digital architecture.
- With its comprehensive cyber security expertise, Materna supports organisations in integrating the requirements of the CRA into their ISMS to ensure that minimum cyber security requirements are met throughout the entire lifecycle of digital products.
- Our EAM and cyber security experts help organisations build transparency – not only for the CRA, but also in conjunction with other EU regulations such as the NIS2 Directive, the EU Data Act and the EU AI Act.
Think holistically, reap multiple benefits
Many of the CRA’s requirements are not new – sectors such as the automotive and medical technology industries have already overcome comparable challenges. Their recipe for success? A holistic IT architecture that integrates regulatory requirements rather than treating them in isolation. This is precisely where Materna comes in: together with our clients, we develop a unified governance, risk and security strategy that responds flexibly to new regulations and safeguards companies in the long term.
Security by Design – getting it right from the start
An integrated ISMS takes regulatory requirements such as the CRA into account across the entire organisation. This encompasses business processes, corporate values, staff and products. This enables the CRA’s requirements to be implemented and demonstrated holistically within the organisation.
Through Enterprise Architecture Management, vulnerabilities are identified at an early stage, measures are systematically documented and IT components are assessed in context – exactly as required by the CRA.
Whether it involves connected products, embedded devices, software solutions or cloud-based components, the integration of ITSM, CMDB and BPM systems creates transparency regarding digital product architectures and their interdependencies. This not only meets the CRA’s requirements but also specifically strengthens the security and compliance strategy.
Take action now: greater resilience, less risk
With the Cyber Resilience Act coming into force, product security becomes a corporate obligation – and an opportunity to actively shape the digital future. Through an integrated ISMS and the development of transparent architectures and intelligent lifecycle management, organisations lay the foundations for greater security, lower risk and sustainable competitiveness.
Want to find out more? Download our latest white paper on the subject here.
Further information on cyber security
Further information on enterprise architecture management