Ahead of the EU Cyber Resilience Act's (CRA) reporting requirements taking effect on 11 September, NCC Group's experts examine what the changes mean for manufacturers and why organisations can no longer afford to delay preparation.
The Cyber Resilience Act enters a significant new phase on 11 September as manufacturers of products within scope become subject to mandatory reporting requirements for actively exploited vulnerabilities and severe security incidents.
Under the new rules, organisations must notify authorities when they become aware of exploited vulnerabilities or serious cyber incidents affecting their products. Importantly, this includes vulnerabilities and incidents within third-party components where a manufacturer's own products are impacted, increasing the focus on software supply chain visibility and oversight.
Louise Horton, Government Affairs Lead at NCC Group commented:
“Over recent years, European policymakers have introduced a number of ambitious cyber security frameworks, including the Cyber Resilience Act, NIS2 and DORA. The challenge now is implementation. For the Cyber Resilience Act, recent guidance from the European Commission, alongside ongoing ETSI standards development, is providing organisations with a clearer picture of what compliance will look like in practice.
"For many organisations, these reporting requirements will be the first real test of operational readiness. Success will depend on having mature vulnerability management processes, visibility across products and dependencies, and the ability to identify, assess and report security issues quickly and accurately.
"Those that are most prepared will have already embedded secure-by-design principles into product development and established strong governance across their software and supply chains. Rather than treating compliance as a series of isolated obligations, organisations should view these requirements as part of a broader cyber resilience strategy.
"With the full requirements of the Cyber Resilience Act due to apply from December 2027, the message is clear: the implementation phase is now well underway, and organisations can no longer afford to defer preparation."
Louise Horton biography
Louise leads UK public affairs for global cyber security firm NCC Group, shaping the organisation’s engagement with government, regulators and key policy influencers. Louise joined NCC Group from the Cabinet Office, where she led on cyber resilience.
Contact
NCC Group Press Office
All media enquires relating to NCC Group plc.