Cyber Resilience Act: When Cybersecurity Becomes Mandatory
On September 24, 2026, a webinar series on the Cyber Resilience Act will begin. Experts will discuss open source, reporting requirements, CRA compliance, and practical implementation in companies.

With the Cyber Resilience Act (CRA), the European Union is fundamentally changing the rules of the game for manufacturers of digital products. What was previously often viewed as the responsibility of IT departments or product security teams is increasingly becoming a strategic issue for senior management as a whole. In particular, the initial reporting requirements—which take effect on September 11, 2026—significantly increase the pressure to act. Companies must report actively exploited vulnerabilities within 24 hours. As a result, a single security vulnerability can suddenly have far-reaching technical, legal, and economic consequences.
Open Source: Practically Indispensable, but Not Risk-Free
Manufacturers of machines, sensors, control systems, and other connected industrial products are particularly affected. This is because modern systems are no longer based exclusively on in-house developed software. Open-source components are standard today and can be found in nearly every software supply chain. While this accelerates development and reduces costs, it also brings new challenges. Ultimately, the responsibility for security issues remains with the manufacturer, even if the cause lies in third-party code.
Greater Transparency in the Software Supply Chain
A central focus of the CRA is transparency regarding the software components used. Software Bills of Materials (SBOMs) are considered an important building block, but they alone are not sufficient to meet the requirements of the regulation. Companies must be able to track at all times which components are built into their products, what risks arise from them, and how to respond in an emergency. With the new concept of the open-source steward, the EU is also creating a clearer framework for responsibilities within the open-source ecosystem.
The EU guidance is intended to provide direction
A new guide from the European Commission provides additional guidance. It explains the CRA’s requirements in greater detail and offers companies initial assistance with practical implementation. Nevertheless, the challenge remains significant: The regulation encompasses numerous technical, organizational, and documentation-related obligations that must be integrated into existing development, quality, and compliance processes.
Cybersecurity as Part of the Product Lifecycle
Practical examples from the industry demonstrate how this can be achieved. Companies such as SICK AG report on how cybersecurity has been gradually established as an integral part of the entire product lifecycle. This makes it clear that regulatory requirements do not necessarily have to be viewed as a burden. Professional vulnerability management, clearly defined processes, and specialized Product Security Incident Response Teams (PSIRTs) not only strengthen compliance but also enhance the security and reliability of products.
Manufacturers Must Act Now
Machinery manufacturers, too, face the challenge of integrating the new requirements into their development processes. Phoenix Contact demonstrates how security requirements can be incorporated into product development at an early stage. At the same time, attention is turning to the question of how the CRA’s requirements can be reconciled with other regulatory frameworks, such as the NIS 2 Directive. Companies that address both issues together can leverage synergies and avoid duplication of effort.
Compliance as a Competitive Advantage
The Cyber Resilience Act makes it clear: Cybersecurity is no longer a purely technical discipline. It is becoming an integral part of product development, risk management, and corporate strategy. Those who implement the new requirements early on not only reduce regulatory risks but also strengthen the trust of customers and partners. In an increasingly interconnected industry, this can become a decisive competitive advantage. After all, in the future, market success will depend not only on functionality and the degree of innovation, but also on the ability to design digital products that are secure and resilient over the long term.











