A company that manufactures products with digital components—such as a router, a business application, or a network management system—discovers that a vulnerability in one of those products is being exploited by a malicious actor to gain unauthorized access to systems, execute code, or install malicious software. From that moment on, even if the analysis of the problem has not been completed, the deadline begins to run: the company has a maximum of 24 hours to issue an initial alert.

 

This is one of the first practical consequences of the entry into force, as of September 11, 2026, of the reporting obligations set forth in Article 14 of the European Union’s Cyber Resilience Regulation, or Cyber Resilience Act (CRA). As of that date, for companies covered by the Regulation, responding to a vulnerability or a serious incident is no longer limited to correcting or mitigating the effects of the detected anomalies.

There are strict reporting obligations that must be followed, and the first step is to determine which products are covered by the Regulation and which companies are considered manufacturers.

Article 14 does not impose a specific internal procedure. However, as an operational recommendation to meet reporting deadlines, it is advisable for the organization to determine in advance who detects and escalates the problem, who decides on and submits the report, and how the technical, legal, management, and communications teams coordinate.

The implementation of Article 14 foreshadows the logic that runs throughout the Regulation: a product’s cybersecurity must be managed throughout its lifecycle and translated into processes that can be activated and verified.

 

Table of Contents

What products are included in the CRA?

The Regulation applies to so-called products with digital elements. This concept encompasses software and hardware products, their remote data-processing solutions, and components sold separately.

To fall within the general scope of the CRA, the intended purpose of the product or its reasonably foreseeable use must include a logical or physical data connection—whether direct or indirect—to a device or a network.

 

Among the products that may be affected are:

  • Applications and operating systems, such as business management software, mobile apps, and operating systems for computers and devices.
  • Connected devices, such as security cameras, sensors, smart thermostats, and connected home appliances.
  • Network management systems, such as platforms used to monitor, configure, or control a corporate network.
  • Interfaces and routers, such as equipment that connects devices, manages traffic, or controls access to a network.
  • Industrial equipment that incorporates software or connectivity, such as machinery, controllers, and connected production systems.
  • Software or hardware components integrated into other products, such as software libraries, communication modules, or microprocessors.

 

The CRA, therefore, is not aimed solely at large technology companies or manufacturers of connected consumer devices. It may also apply to industrial companies and manufacturers in other sectors when their products incorporate software or connectivity and meet the conditions set forth in the Regulation.

The notification obligations also apply to products covered by the CRA that were placed on the market before its full implementation, scheduled for December 2027. Companies should bear in mind that their preparations cannot be limited to new developments or to products that will be marketed starting in 2027.

Certain products subject to specific sector-based regulations—such as medical devices and in vitro diagnostic products, certain vehicles, and certified aeronautical products—are excluded from the scope of the CRA, as are those developed exclusively for military or national security purposes. A standalone cloud-based software service is also excluded when it is not part of a product’s remote data processing solution.

 

The manufacturer, who is primarily responsible for the notification

The primary party subject to Article 14 is the manufacturer of the product containing digital elements. The Regulation defines a manufacturer as the natural or legal person who develops or manufactures these products—or commissions their design, development, or manufacture—and markets them under their own name or brand. This definition applies regardless of whether the product is offered in exchange for payment, through other forms of monetization, or free of charge.

In the case of free software, one exception must be taken into account: the CRA does not apply to free and open-source software developed or provided outside a commercial activity.

The definition requires looking beyond who programmed the software or physically assembled the device—for example, a printer. A company may be considered a manufacturer even if it has commissioned a third party to design or manufacture the product, provided that it markets the product under its own name. An importer or distributor also qualifies as a manufacturer if it markets the product under its own name or brand. It also qualifies if it makes a substantial modification to a product already on the market.

Therefore, the analysis must examine the role the company plays in the value chain and determine which products it markets under its own responsibility.

 

Does the CRA affect manufacturers outside the European Union?

Yes. The determining factor is not where the company is headquartered, but whether it markets a product with digital elements in the European Union. A manufacturer based in the United States, the United Kingdom, China, or any other third country must comply with the notification obligations when its products are made available on the European market. The foreign manufacturer retains its responsibilities, even if it operates through authorized representatives, importers, or distributors established in the European Union.

The Regulation thus covers the entire supply chain: manufacturer, authorized representative, importer, and distributor.

 

A business impact that is difficult to quantify

There is no official census of Spanish companies subject to the CRA. As a reference for the potential scale of the change, the National Institute of Statistics counted 82,323 companies in the information and communication technology (ICT) sector in Spain in 2024, the most recent year for which data is available.

This figure does not equate to the number of companies subject to the CRA. On the one hand, not all companies in the ICT sector manufacture products with digital components—as is the case, for example, with many consulting firms. On the other hand, the CRA may affect manufacturers in other sectors whose products incorporate software or connectivity.

At the European level, the impact assessment prepared by the Commission prior to the adoption of the Regulation used as a reference a market consisting of 365,759 software companies and 22,773 ICT hardware manufacturers, based on 2019 data.

The vast majority were small and medium-sized enterprises: 99.7% in the analyzed sample of the software market and 97.1% among hardware manufacturers. These figures show that adapting to the CRA is not a challenge reserved solely for large technology companies.

 

For Saima Systems, as a manufacturer of proprietary connectivity and cybersecurity technology, the new framework confirms a central idea: product security requires monitoring, vulnerability management, response capabilities, and coordinated communication when a problem arises.

The second part, “Cyber Resilience and CRA: A Guide to Reporting Vulnerabilities and Serious Incidents (Part II)” will explain how to identify situations that must be reported and will address the deadlines and internal response procedures.