In brief: The Cyber Resilience Act mandates transparency and traceability of software components, shifting business models from license sales toward lifecycle-based responsibility assumed by IT service providers.
The Cyber Resilience Act (CRA) obliges companies to establish traceable, secure software supply chains, placing open, transparent architectures at the center of modern IT security strategies. For CISOs, this changes not only technical requirements but also responsibilities toward manufacturers and service providers.
The CRA addresses a problem that has long been a reality in many companies: software and digital infrastructures are so tightly intertwined that security can no longer be treated as an afterthought. Topics such as supply chain security, Software Bill of Materials (SBOM) and CVE management are gaining significant importance as a result. Going forward, companies must be able to fully trace which components are built into their systems, where risks lie, and how vulnerabilities are swiftly identified and remediated. Open, transparent software building blocks prove advantageous here, as they enable automatable, modular and traceable structures — properties that are increasingly indispensable for resilient operation of modern IT environments.
This shift is particularly evident in network and security architectures. Open source is no longer confined to individual development teams or specialized applications but is increasingly forming the foundation for scalable enterprise environments. Technologies such as Kubernetes, containerized systems and Infrastructure-as-Code, as well as open-source tools for automation, compliance management and software administration, are already changing day-to-day operations. From a technical perspective, these developments are converging into three central competency fields: platform engineering, automated operations, and security-by-design across the entire software supply chain.
For managed service providers (MSPs) and IT service providers, this development carries significant economic consequences. The previous business model, heavily based on license margins and the resale of proprietary solutions, is coming under pressure. Value creation is increasingly generated through in-house delivery — such as platform operations, managed services with robust SLAs, or consulting ranging from analysis to architecture recommendations. This shift from “license margin” to “lifecycle value” is also changing the yardstick by which providers are assessed: what matters is no longer solely the product sold, but the support provided across the entire lifecycle.
This has a concrete consequence for CISOs when selecting partners: whoever supports customers across the entire lifecycle also assumes the responsibility that was previously distributed among manufacturer, service provider and customer. Providers that consistently bundle integration, operations and compliance position themselves as a “single point of liability” — particularly in complex, regulated environments, this bundling becomes a key differentiator. It is not the individual license or component that matters, but the question of who ultimately stands accountable for the overall system. A complete transition to open architectures will not happen in the short term, however: existing system landscapes, regulatory dependencies and complex legacy environments are slowing the transformation.
Source: www.it-daily.net · Published August 4, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.