Get in touch

We are here to assist you

Contact us widget

Contact us widget on every page

"*" indicates required fields

By submitting this form, you are confirming that you have read and agree to Eurotech’s Privacy Policy
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
October 5, 2026

The Cyber Resilience Act is a market test, not just a compliance deadline

 

 

 

Most conversations about the Cyber Resilience Act start in the wrong place.

 

Engineering teams focus on what the regulation requires, and legal teams focus on when the deadlines land, but the question that actually matters for the business rarely gets asked: who gets how impacted in the market once the CRA is enforced, and who gets to set the new terms of trust with customers and partners?

This is the conversation worth having, because the CRA is best understood not primarily as a compliance exercise but as a market-positioning one. By the time the deadlines force every manufacturer to act, the ones who treated this as a strategic bet rather than a legal obligation will already have built the advantage.

Compliance is the baseline, not the strategy

 

The obligation to report actively exploited vulnerabilities begins on September 11, 2026, and full conformity is required by December 11, 2027. Those dates matter, but they describe the minimum a manufacturer needs to remain on the European market, not what it takes to win share within it.

The CRA sets a common cybersecurity baseline for digital products, and every serious competitor will eventually clear that baseline because there will be no other option. Meeting the requirement, on its own, differentiates no one. What sets a manufacturer apart is how and how early it got there, how much of the underlying work was genuinely built into the platform rather than bolted on ahead of an audit, and how convincingly it can demonstrate that work, beyond the CE marking that  signals to the market that a product meets the applicable EU requirements.

What I’m hearing across our markets

 

Eurotech operates within industrial automation, transportation, energy, and aerospace and defence, sectors where a compromised device is never a mere inconvenience: it can mean a production line down, a substation exposed, or a fleet grounded. Customers in these spaces have increasingly been asking more  than expected with regards to CRA requirements, more that go beyond “Are you compliant” or “Can I still be buying from you in 2028?“

 

That is a procurement question rather than a legal one. System integrators and OEMs are already building CRA readiness into their supplier scorecards, because they inherit the exposure the moment they integrate a non-compliant component from someone else. Suppliers who cannot answer with confidence are being quietly removed from shortlists, often months before any regulator becomes involved.

Secure by design is a platform decision, not a project

 

The manufacturers pulling ahead in cybersecurity are not necessarily the ones with the best compliance spreadsheet. More often, they are the ones that make appropriate choices in the context of hardware and software platform and a secure development process, years earlier, that already provided:

 

  • Certified secure development process like IEC 62443-4-1.
  • Strong standards-based device identities.
  • A hardware Root of trust – a TPM 2.0 or Secure Element – instead of a plan to add one later.
  • Signed, over-the-air (OTA) updates that can patch a fleet without a truck roll.
  • A proper Software Bill of Materials (SBOM) that shows, in minutes, which products are affected when the next vulnerability appears.

 

These are examples for decisions affecting product architecture, an architecture that is very difficult to retrofit into a device that has already been developed.

The advantage goes to whoever moves early. It is a far stronger position to explain why an organisation invested early than to explain why it is scrambling in the third quarter of 2027. Every month between now and December 2027 is a month in which a first mover can turn cybersecurity readiness into a sales conversation, while a fast follower is still writing documentation.

 

That is the reframe worth making across the industry: rather than asking what the CRA requires, manufacturers should be asking what it lets them prove to the market experience and preparedness beyond what their competitors can.