The Cyber Resilience Act explained

Two colleagues in cyber data team monitoring computer technology in office

The deadline for the EU Cyber Resilience Act is fast approaching, forcing leaders to take immediate action. The Cyber Resilience Act will fundamentally change the security obligations attached to every product manufacturers ship to the EU.

The act aims to make products secure by design, secure by default, and secure throughout their lifecycle. It makes strong cyber security a prerequisite for market access.

Businesses must act now to navigate a patchwork of expanding cyber risk, governance, and compliance legislation. But there’s a disconnect: More than a half (51%) of organisations make limited or no investment in regulatory tracking, according to the ServiceNow 2026 Risk and security outlook. This impacts an organisation’s ability to properly prepare for the regulatory impact.

What is the Cyber Resilience Act?

The Cyber Resilience Act is a regulation that builds on existing rules to enhance cyber security standards in the EU. It’s designed to protect consumers and businesses from vulnerabilities in software and hardware products.

Under the act, organisations must:

The act entered into force on 10 December 2024, with obligations phased in over the following three years. Starting 11 September 2026, product manufacturers must report security incidents or known exploits to the Computer Security Incident Response Team (CSIRT) of the relevant authorities within 24 hours.

The act’s full weight will apply starting on 11 December 2027, when national market surveillance authorities begin enforcement. For product manufacturers, the act will require full transparency on security breaches at a legislative level. The regulation has a global reach, meaning any vendor selling inside the EU must comply to retain market access.

Non-compliance can result in severe penalties, including withdrawal of products from the market and fines of up to €15 million or 2.5% of the company’s total revenue for the previous financial year—whichever is higher.

For most organisations, the practical effect will be faster, more frequent security updates for the products they buy.

How can a business become secure by design?

The Cyber Resilience Act highlights the importance of becoming secure by design—building cyber resilience into operations and the software development lifecycle. This approach helps ensure resilience is proactive rather than tested only in the wake of an incident.

All organisations can take steps to make their software and procurement secure by design:

  1. Embed compliance in product development: Incorporate security risk assessments into design stages to help define the necessary controls required for the product to comply with the Secure by Design framework. This has multiple benefits, including the ability to implement continuous control monitoring, automated evidence collection, and regulatory change tracking.

  2. Track security markings: Monitor conformity marks and third-party or vendor security commitments inside the system where you manage third-party risk. Apply the control framework to continuously monitor performance—not just at defined intervals or from time to time.

  3. Incorporate vulnerability management: Continuously identify vulnerabilities and provide disclosure to clients, as well as security updates. Craft patching processes that are well defined and rigorous in execution.

  4. Govern access: Access control is one of the act's essential product requirements. Products must ensure protection from unauthorised access by appropriate control mechanisms, including authentication and identity or access management systems, and report on possible unauthorised access.

  5. Test resilience regularly: Strengthen your security posture through ongoing scenario, impact, and tolerance testing to help ensure your business remains operational during incidents. This will also require asset dependency mapping, including third parties.

  6. Maintain a software bill of materials (SBOM): Document and provide a full inventory of components with the sale of your product. This will enable your clients’ security teams to efficiently identify where vulnerabilities exist.

How does ServiceNow support regulatory compliance?

With 24 hours to report an incident, organisation needs to move quickly to assess the scope of an event, then agree on what needs to be reported to the regulator and clients. ServiceNow works with organisations to merge multiple data sources into one view, prioritise vulnerabilities and threats associated with assets, minimise the blast radius, and remediate problems within the time constraints imposed by any regulator.

Meeting strict incident reporting timelines requires speed and total visibility. ServiceNow Security Incident Response unites security workflows on a single platform, helping teams rapidly identify exploited vulnerabilities. This replaces manual tracking with automations that protect infrastructure and compliance.

For attack surface minimisation, Armis from ServiceNow discovers and inventories every connected asset in real time. Then through Unified Security Exposure Management, the solution will consolidate exposure/misconfiguration findings against an asset inventory of more than 7 billion devices.

Armis continues to passively monitor network traffic to flag anomalous device behaviour that could degrade shared network/service availability.

The Cyber Resilience Act mandates that manufacturers assess security risks during product planning and design. ServiceNow Integrated Risk Management helps organisations manage against their operational resilience plans, evaluating and monitoring risks, including controls, through the entire product lifecycle.

Powered by a single system of action, the product allows you to demonstrate the auditable process behind making products secure.

If and when a cyber attack strikes, ServiceNow Business Continuity Management helps organisations quickly identify the affected assets, businesses, and critical processes of their operation. Then business continuity plans can be executed with precision via the automated disaster recovery workflows.

Security teams can leverage the dependency map across critical business processes to practice multiple scenarios so that they’re well trained when an event happens.

Relying on manual spreadsheets and fragmented communications to track third-party system performance leaves the enterprise exposed to supply chain blind spots. ServiceNow Third-Party Risk Management enables organisations to centralise the tracking of their multi-dimensional risk profile and identify potential weaknesses in the extended ecosystem.

ServiceNow’s SBOM capability helps organisations strengthen software security, manage vulnerabilities, and mitigate compliance risks in the supply chain. It does this by correlating the vulnerabilities to components of the SBOM, and it prioritises remediation activity based on the criticality of the organisation’s business processes.

For identity governance, ServiceNow Access Graph directly addresses the Cyber Resilience Act’s access-control and least-privilege requirements (Part I.2) across a scope broader than traditional identity and access management. These are increasingly relevant as products covered by the act embed autonomous AI components.

With ServiceNow’s comprehensive portfolio of solutions for cyber and risk management, organisations can automate many of the requirements associated with the Cyber Resilience Act to avoid last-minute panic.

Find out more about how ServiceNow can help you build resilience with AI-driven risk and security.