The EU Cyber Resilience Act Is Turning Security into a Market Access Requirement
Starting September 11, new EU reporting obligations extend to communications platforms and give procurement teams a concrete set of questions to ask before the next contract renewal.
Sep 10, 2026
·Blog
·Secure Communications
%3Aquality(100)&w=3840&q=75)
The first hard deadline of the EU Cyber Resilience Act (CRA) takes effect this week. Starting September 11, 2026, manufacturers placing products with digital elements on the EU market must report actively exploited vulnerabilities within 24 hours of becoming aware of them. A more detailed notification is due within 72 hours, followed by a final report within 14 days of a corrective measure becoming available. A parallel trigger covers severe cybersecurity incidents that affect the product's security. In those cases, the final report is due within one month of the 72-hour notification.
Both obligations apply to products already on the market, not only to new releases, and both fall on the manufacturer, whether the product is hardware, software, or a connected service. Any messaging or coordination platform operating in the EU now carries this obligation directly.
Security Stopped Being a Discretionary Investment
Before the CRA, a vendor could choose how much to invest in product security and how much to speak about it publicly. That choice is gone. By December 11, 2027, every product with digital elements must be secure by design, ship without known exploitable vulnerabilities, carry a declared support period of at least five years (unless the expected lifetime of the product is naturally shorter), and keep each issued security update available for a minimum of 10 years after that update is issued, or for the remainder of the support period, whichever is longer. Full conformity, technical documentation, a machine-readable Software Bill of Materials (SBOM), and CE marking all come due on that same date. Security becomes a documented, auditable condition of staying on the EU market, not a claim a vendor gets to make unchallenged.
Non-compliance carries consequences beyond a fine. Market surveillance authorities can order corrective action, product withdrawal, or an outright recall, on top of financial penalties that reach €15M or 2.5% of total worldwide annual turnover for breaching the essential requirements or the obligations in Articles 13 or 14, whichever figure is greater. Any organization still running sensitive coordination through a vendor that cannot answer these questions now carries regulatory exposure on top of operational risk.
Why the Stakes Run Higher for Communications Platforms
A vulnerability in a spreadsheet application is contained. A vulnerability in the platform an organization uses to coordinate sensitive operations, leadership communications, and incident response can become a single point of failure for everything routed through it, including the response to the incident itself. Communications tools have a history of being selected on features, price, and how familiar the interface feels. Security posture was rarely a primary requirement. Using the tools that users were accustomed to in their consumer life felt easier to justify than security-driven decisions. The CRA changes the procurement question permanently because vulnerability handling must now be documented and auditable, with a paper trail a buyer is entitled to request and review.
Questions to Ask Your Communications Vendor
When evaluating a vendor's EU CRA compliance, ask for specifics, not reassurance.
Do they have a working Article 14 reporting pipeline in place today, not a plan for one, since that obligation applies to products already on the market?
What is their declared support period for the product you're buying? Ask specifically whether that period was set to match the product's actual expected use, not just the five-year CRA minimum.
How will they evidence security update availability for each patch they issue? That commitment runs for years after each individual update, not just for the life of the contract.
Can they produce a machine-readable SBOM today, or is that still on their roadmap toward the December 2027 deadline?
What happens under the CRA if they get it wrong? A vendor that can't speak plainly about their own penalty exposure likely hasn't thought hard about yours either.
A Regulation Forcing the Market's Hand
The CRA doesn't invent a new standard so much as it forces a question the market should have been asking all along: is this platform built for continuous, provable security governance, or was that governance bolted on when the law required it? For any organization currently coordinating sensitive work over a platform chosen for convenience rather than architecture, the reporting deadline landing this week is a reasonable moment to find out which one you're running.
The EU Cyber Resilience Act Is Turning Security into a Market Access Requirement
Starting September 11, new EU reporting obligations extend to communications platforms and give procurement teams a concrete set of questions to ask before the next contract renewal.
Sep 10, 2026
·Blog
·Secure Communications
%3Aquality(100)&w=3840&q=75)
The first hard deadline of the EU Cyber Resilience Act (CRA) takes effect this week. Starting September 11, 2026, manufacturers placing products with digital elements on the EU market must report actively exploited vulnerabilities within 24 hours of becoming aware of them. A more detailed notification is due within 72 hours, followed by a final report within 14 days of a corrective measure becoming available. A parallel trigger covers severe cybersecurity incidents that affect the product's security. In those cases, the final report is due within one month of the 72-hour notification.
Both obligations apply to products already on the market, not only to new releases, and both fall on the manufacturer, whether the product is hardware, software, or a connected service. Any messaging or coordination platform operating in the EU now carries this obligation directly.
Security Stopped Being a Discretionary Investment
Before the CRA, a vendor could choose how much to invest in product security and how much to speak about it publicly. That choice is gone. By December 11, 2027, every product with digital elements must be secure by design, ship without known exploitable vulnerabilities, carry a declared support period of at least five years (unless the expected lifetime of the product is naturally shorter), and keep each issued security update available for a minimum of 10 years after that update is issued, or for the remainder of the support period, whichever is longer. Full conformity, technical documentation, a machine-readable Software Bill of Materials (SBOM), and CE marking all come due on that same date. Security becomes a documented, auditable condition of staying on the EU market, not a claim a vendor gets to make unchallenged.
Non-compliance carries consequences beyond a fine. Market surveillance authorities can order corrective action, product withdrawal, or an outright recall, on top of financial penalties that reach €15M or 2.5% of total worldwide annual turnover for breaching the essential requirements or the obligations in Articles 13 or 14, whichever figure is greater. Any organization still running sensitive coordination through a vendor that cannot answer these questions now carries regulatory exposure on top of operational risk.
Why the Stakes Run Higher for Communications Platforms
A vulnerability in a spreadsheet application is contained. A vulnerability in the platform an organization uses to coordinate sensitive operations, leadership communications, and incident response can become a single point of failure for everything routed through it, including the response to the incident itself. Communications tools have a history of being selected on features, price, and how familiar the interface feels. Security posture was rarely a primary requirement. Using the tools that users were accustomed to in their consumer life felt easier to justify than security-driven decisions. The CRA changes the procurement question permanently because vulnerability handling must now be documented and auditable, with a paper trail a buyer is entitled to request and review.
Questions to Ask Your Communications Vendor
When evaluating a vendor's EU CRA compliance, ask for specifics, not reassurance.
Do they have a working Article 14 reporting pipeline in place today, not a plan for one, since that obligation applies to products already on the market?
What is their declared support period for the product you're buying? Ask specifically whether that period was set to match the product's actual expected use, not just the five-year CRA minimum.
How will they evidence security update availability for each patch they issue? That commitment runs for years after each individual update, not just for the life of the contract.
Can they produce a machine-readable SBOM today, or is that still on their roadmap toward the December 2027 deadline?
What happens under the CRA if they get it wrong? A vendor that can't speak plainly about their own penalty exposure likely hasn't thought hard about yours either.
A Regulation Forcing the Market's Hand
The CRA doesn't invent a new standard so much as it forces a question the market should have been asking all along: is this platform built for continuous, provable security governance, or was that governance bolted on when the law required it? For any organization currently coordinating sensitive work over a platform chosen for convenience rather than architecture, the reporting deadline landing this week is a reasonable moment to find out which one you're running.
%3Aquality(100)&w=3840&q=75)