The Cyber Resilience Act imposes from this Friday the notification of cyberattacks and sanctions of up to 15 million.

The Cyber Resilience Act debuts this Friday its obligations for reporting cyberattacks, with strong penalties and new requirements for the entire sector.

4 minutes

fotonoticia 20260909123237 1920

fotonoticia 20260909123237 1920

Add DEMÓCRATA to Google

Ask FREN

Published

4 minutes

Most read

Starting this Friday, September 11, the field of cybersecurity in the European Union enters a different phase with the implementation of the Cyber Resilience Act, a regulation that requires companies to report actively exploited vulnerabilities and serious incidents that compromise the security of their digital products, with penalties that can reach 15 million euros.

Cyber threats are transforming at great speed and, in this scenario, organizations are redefining their approach to strengthen their resilience, not only in response to an attack but also in preparing their teams, early detection of risks, and designing defensive strategies capable of growing at the same pace as their technological environments.

In this context, the European Union seeks to ensure that companies move in that direction and accelerate the paradigm shift in cybersecurity. With this goal, the Cyber Resilience Act (CRA) was created, a regulation that sets mandatory security requirements for 'hardware' and 'software' products with digital components marketed within the community market.

The regulation, in force since December 2024, extends from applications to all types of devices and software programs - 'smartphones', operating systems, 'routers', baby monitors, smartwatches, firewalls, among others - which must comply with minimum cybersecurity standards, proportional to the level of risk associated with each product.

With this, the European Commission wants to address frequent problems in many digital products, such as insufficient protection levels or the lack of timely updates, "while companies and consumers have difficulties identifying which products offer adequate guarantees," as stated by the IT solutions distributor, Ingram Micro.

From its position in the market, the company observes the role of manufacturers, partners, and customers in terms of security and can analyze both current needs and the effect that the new regulation will have on companies.

"Organizations need to anticipate, know the risks associated with their infrastructure, and have a strategy that allows them to react quickly when an incident occurs. The Cyber Resilience Act precisely reinforces this vision of security throughout the technology lifecycle," stated Martin Trullás, Director of Advanced Solutions at Ingram Micro, regarding this.

New phase of the CRA: the obligation to report incidents begins

Before all the obligations of the Cyber Resilience Act, scheduled to take full effect on December 11, 2027, are fully applied, the distributor reminds that companies are already facing an intermediate stage, which begins this Friday, September 11, and that, if not addressed properly, can lead to "significant" consequences.

Specifically, starting this Friday, the reporting obligations will be activated: manufacturers will have to communicate the vulnerabilities that are being exploited and the serious incidents that impact the security of their products with digital elements.

The regulation also establishes that these incidents must be reported quickly, setting an early notice within a maximum of 24 hours from when the problem is detected and a more complete report, with all relevant information, within a maximum of 72 hours.

However, Ingram Micro emphasizes that the goal of the CRA is not limited to having companies report their incidents, but incorporates cybersecurity requirements that encompass the planning, design, development, and maintenance of products, with the obligation to manage vulnerabilities throughout their lifecycle.

This philosophy is based on the premise that security "cannot be added at the end of the process," but "must be part of the technology from the moment it is designed and accompany it throughout its useful life," as Trullás has assured.

Therefore, the executive believes that organizations must review their internal processes and ensure that manufacturers, distributors, partners, and customers "work in an even more coordinated way," something that usually requires a prolonged adaptation period. Hence, 2027 should not be understood as the date to start preparing, since, in Trullás's words, "the first change comes this September."

In the most serious cases of non-compliance with the regulations, companies are exposed to fines of up to 15 million euros or 2.5 percent of their global annual turnover, applying the amount that results in the highest.

Cybersecurity throughout the entire value chain

Ingram Micro also emphasizes that the CRA does not solely fall on the manufacturer, but sets obligations for the different economic operators involved in bringing the digital product to market.

In this way, the requirements of the regulation must be met throughout the value chain. This implies knowing what technology is integrated into the infrastructure, how its vulnerabilities have been addressed, what type of updates it will receive, and what guarantees the manufacturer offers during the support period, as detailed by the company.

In practice, the technological decisions of organizations must incorporate cybersecurity as a central criterion. Thus, for example, a company that renews its equipment with connected video surveillance cameras will no longer only value performance or price, but will have to "know how possible vulnerabilities will be managed, how long they will receive security updates, or what mechanisms exist to respond to an incident." Protection thus becomes a shared responsibility.

For this reason, European regulations require that companies and users can clearly identify the services and products that meet adequate levels of cybersecurity, which must carry the 'CE' marking that certifies their compliance with the legal requirements of the European Union for their marketing.

"Threats will continue to evolve regardless of the regulatory calendar. However, those organizations that take advantage of this period to anticipate will not only be better prepared to comply with the new framework but also to face an increasingly complex cybersecurity scenario and be more resilient," Trullás has stated.

In this scenario, Ingram Micro insists that, according to its experience, "the technology channel can play a relevant role as a link between manufacturers, partners, and customers." As a global distributor, and thanks to its broad ecosystem of technology providers and security specialists, the platform claims that it can facilitate access to solutions and knowledge to "strengthen the protection of its customers" in this new stage marked by the Cyber Resilience Act.

Hola, soy Fren. ¿Cómo te ayudo?