

#222 | Cyber Resilience Act for OEMs: From Compliance Evidence to a Lifecycle Service | Cumulocity
www.iotusecase.com #CyberResilienceAct #CRA #NIS2 How does a legal reporting duty turn into a service you can charge for? That is the question behind “Cyber Resilience Act for OEMs: From Compliance Evidence to a Lifecycle Service” on the IoT Use Case Podcast. Host Ing. Madeleine Mickeleit talks to Miguel Morales, Vice President Strategic Cloud Alliances at Cumulocity, about what the CRA asks of connected-product manufacturers and where it meets NIS2. Podcast Summary The CRA comes with two dates: from September 2026, manufacturers have 24 hours to report actively exploited vulnerabilities and severe incidents; from December 2027, full conformity applies. Morales draws the line between the two regulations – the CRA governs manufacturers and their products, NIS2 the operators, with personal liability attached. That intersection is where his argument sits. CRA obligations stop at disclosing vulnerabilities and making patches available, and the patches must be free. Operators, though, have to prove their own compliance across equipment from many vendors. A manufacturer who hands them that evidence automatically is selling a lifecycle service, not just hardware. A published cybersecurity paper from Danfoss serves as the reference point. Beyond that, the conversation stays technical: SBOM generation, continuous firmware scanning, PKI certificates and update rollouts across globally distributed fleets. Morales calls the manual effort behind this the governance tax, and closes with ten actions for manufacturers. What you take away The first deadline is September 2026, not December 2027: 24-hour reporting for actively exploited vulnerabilities starts then. CRA and NIS2 interlock – the manufacturer’s obligation is the basis of the operator’s own proof. The patch must be free under the regulation; what can be priced is the rollout orchestration and the auditable evidence. Compliance shifts from an annual reporting exercise to a status calculated continuously from device state data. First of Morales’ ten actions: move CRA ownership out of legal and into the product P&Ls. ----- Relevante Folgenlinks: Madeleine (https://www.linkedin.com/in/madeleine-mickeleit-mrs-iot/) Miguel (https://www.linkedin.com/in/moralesamiguel/) CRA and NIS2 compliance (https://www.cumulocity.com/resource-library/cumulocity-eu-regulation-white-paper/) Cumulocity and EY Law (https://www.cumulocity.com/resource-library/building-cyber-resilience-for-the-eu-market/) Jetzt IoT Use Case auf LinkedIn folgen 1x monatlich IoT Use Case Update erhalten
- Transcript

















