Skip to content

Cyber Resilience Act: New Guidelines Tighten Vendor Management Requirements

The point: The CRA requires manufacturers from September 2026 onwards to report actively exploited vulnerabilities, demanding full transparency on machine identities and secrets in the supply chain earlier than the December 2027 deadline.

The European Commission has published guidelines on the Cyber Resilience Act that provide manufacturers with specific compliance requirements. A previously overlooked point is the duty of care towards third-party providers, cloud infrastructures and all integrated components.

With the new guidelines, the European Commission clarifies previously contentious points of the Cyber Resilience Act (CRA): the treatment of open-source software, the definition of material changes in software updates, and the specification of support periods. In doing so, it provides software vendors and manufacturers with more concrete guidance for implementing one of the most significant EU laws on cybersecurity.

The actual compliance challenge, however, lies in the duty of care towards third-party providers and their components as required by the CRA. The CRA extends a manufacturer’s responsibility beyond self-developed code: it also covers integrated components, utilised infrastructure providers, as well as machine identities and access credentials (secrets) through which data is exchanged between these elements. According to a Keeper study from 2026, a quarter of German companies already cite insufficient control over third-party access as a governance weakness. The new guidelines do not close this gap; however, they establish a binding timeline for its elimination.

A critical point in time is 11 September 2026: from this date onwards, reporting obligations apply for actively exploited vulnerabilities, significantly earlier than the general CRA compliance deadline in December 2027. Companies that only begin building transparency on non-human identities in 2027 risk missing these reporting obligations.

Central to compliance preparation is comprehensive management of machine identities, API keys, tokens and service accounts across all development and integration processes. This central control over secrets enables manufacturers to demonstrate the supply chain diligence required by the guidelines. Anyone who has not completed this measure by September 2026 cannot meet the mandatory reporting requirements on time.


Source: www.it-daily.net · Published 30 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: