The EU Cyber Resilience Act (CRA) imposes 24-hour incident reporting rules and strict supply chain oversight on software and hardware makers.
Manufacturers selling products with digital elements inside the EU must establish security processes across the entire product lifecycle, accounting for maintenance and patches up to five years post-launch. The regulation creates a unified baseline across the single market, establishing mandatory requirements intended to formalise secure-by-design engineering from early development stages.
Maurice Kalinowski, Director of Product Management for Qt Framework at Qt Group, says: “Embedding vulnerability management, documentation, and security assessments will evolve the way in which we manage product lifecycles and updates, creating a complete lifecycle.
“New product development processes can continue, unhindered by the usual late-stage vulnerabilities of the last iteration, making way for new innovation.”
Out-of-context design and SBOM compliance
The regulation expands the compliance perimeter beyond traditionally-regulated sectors such as automotive, aerospace, medical devices, and industrial automation.
Developers building individual software libraries or embedded components must now prove secure design, maintain active patching regimes, and provide a clear Software Bill of Materials (SBOM). This creates operational difficulties for suppliers designing components out of context, where the final deployment environment or host device remains unknown during initial development.
Andrew Longhurst, Managing Director at Wittenstein High Integrity Systems, explains: “Component and platform providers have a key part to play here. They need to give developers the secure-by-design architecture and evidence they need to demonstrate compliance, without forcing rigid architectures and closed ecosystems.”
24-hour reporting windows and AI agents
Under the CRA, organisations must notify the European Union Agency for Cybersecurity (ENISA) and competent national authorities within 24 hours of identifying an actively exploited vulnerability or severe incident.
This requirement also applies to UK manufacturers that maintain EU supply chains or sell products directly into the bloc. Compliance tracking must also cover autonomous software agents and machine identities operating across production pipelines.
Gregg Hardie, Public Sector Regional Vice President at SailPoint, comments: “Securing human access is hard enough, but now – in the shape of AI agents – manufacturers have to gain understanding and control of their ‘digital workforce’: non-human identities which can act autonomously throughout supply chains, and which move across systems and networks at machine speed, often with broad access permissions.
“Governing agents begins with getting a picture of how many agents there are and an understanding of what they can access. Not knowing is not a defence under the Act, making it a must for all identities – human and machine – to be subject to comprehensive oversight in what are often extremely complex environments.”
Dependency tracing across software components
Meeting early reporting windows requires immediate visibility into external dependencies.
Data from Sonatype indicates that the average software supply chain contains over 180 external components. In 2025, the firm tracked nearly 1.8 billion component downloads that contained known security risks with available, yet unapplied, fixes.
Ilkka Turunen, Field CTO at Sonatype, explains: “The CRA makes every risk from every adopted component the concern of the organisation using it. When a vulnerability affecting any one adopted component is actively exploited, teams now have a 24-hour deadline to report it to ENISA and their local regulator.
“Teams need to know which products contain the affected components, which versions are exposed, and inform both the regulator and their customers. If that picture has to be reconstructed manually during an incident, the reporting window will be nearly impossible to meet.”
Incident reporting versus operational recovery
Tight reporting deadlines force corporate boards to establish operational protocols before an intrusion occurs. Organisations risk diverting resources from incident remediation to regulatory disclosures if governance lines remain ambiguous during an attack.
James Blake, VP of Global Cyber Resiliency Strategy, Response & Consulting Services at Cohesity, warns: “Reporting must also not happen at the expense of recovery. Every hour spent satisfying the clock is an hour taken away from restoring the business, so clear roles and separate reporting ownership are essential to keeping recovery on track.”
Blake notes that governance teams must determine who holds authority to approve initial notifications at irregular hours, and which specific territorial regulations apply to the affected assets.
Parallel regulatory developments in the UK mirror this enforcement posture. Proposed expansions to the UK Cyber Security and Resilience Bill introduce statutory powers allowing government intervention when technology suppliers pose national security risks.
The measure follows warnings from the National Cyber Security Centre (NCSC) regarding state-sponsored activities, including an incident that forced a UK power station offline for four days. Implementation requirements across both jurisdictions mandate tested offline backups, network segmentation, continuous third-party risk monitoring, and rehearsed response workflows across external supply chains.
See also: Visa updates open-source VVAH tool with vulnerability remediation

Want to learn more about cybersecurity from industry leaders? Check out Cyber Security & Cloud Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the AI & Big Data Expo. Click here for more information.
Developer is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.