Cyber Resilience Act and the challenges of supply chain security: reporting obligations, verification, standards and OT security

Cyber Resilience Act and the challenges of supply chain security: reporting obligations, verification, standards and OT security

Cyber Resilience Act and the challenges of supply chain security: reporting obligations, verification, standards and OT security

With the Cyber Resilience Act (CRA) coming into force, companies in the EU are facing a number of new challenges, particularly with regard to reporting obligations and ensuring security in the supply chain. These new regulatory requirements are intended to help strengthen cyber security in the EU and increase resilience against cyber attacks. However, implementation requires not only technical expertise, but also systematic organisation and clear processes. In the following, we highlight the most important points that companies need to consider as part of the CRA and the NIS2 directive, with a particular focus on OT security.

OT security: securing industrial systems 

Optional technology (OT) security is a particularly critical area that often receives too little attention. This includes all systems and devices that are used in production, logistics or infrastructure. These systems are often particularly vulnerable to cyber attacks, as they have frequently not been adequately secured in the past and sometimes still use older operating systems and unsecured network protocols.

In the context of the CRA and the NIS2 directive, companies must also bring their OT security measures up to date. This means that they must not only protect their IT systems, but also all industrial control systems and IT-OT connectivity. Security gaps in OT can not only lead to significant production downtime, but also pose safety risks for employees and the environment.

OT security comprises various measures:

In order to be able to take out cyber insurance, insurers expect preventive security measures to be implemented. These include:

  • Segmentation of networks: It is essential to separate IT and OT in order to minimise attack vectors.

  • Vulnerability management: Regular updates and patches must also be carried out in OT systems.

  • Access controls and monitoring: Access to OT systems should be strictly controlled and monitored to prevent unauthorised access.

  • Security audits: Regular audits and penetration tests are necessary to identify and eliminate vulnerabilities in OT systems at an early stage.

Security in OT is not only important from a technical perspective, but also from an organisational one. In many companies, there are often still separate IT and OT departments that do not always work closely together. To ensure comprehensive cyber resilience, these areas must be increasingly integrated and cooperation promoted.

Reporting obligations in the Cyber Resilience Act: transparency and responsibility for manufacturers

With the Cyber Resilience Act (CRA) coming into force in December 2024, the reporting obligations for manufacturers will be significantly tightened. Companies that discover a serious security vulnerability in their products or are affected by a vulnerability must not only document it internally, but also report it to the relevant authorities, such as the National Security Agency (NSA). This reporting obligation will become an integral part of the entire Cyber Resilience Act (CRA), which obliges companies to deal with security vulnerabilities transparently.

This is not just about the simple creation of reports, but also about the introduction of clear internal processes. Who checks the reported vulnerabilities for their relevance and affiliation to specific products? What steps need to be taken to eliminate a potential threat? The assignment of responsibilities and the proper processing of reports received via public channels, such as a security email address, present companies with major challenges. Many companies have not yet adequately defined these processes and urgently need to do so in order to meet the requirements of the Cyber Resilience Act. 

Supply Chain Security: A key topic for the future

Another important component of the CRA is the requirements for securing the supply chain. Particularly in the manufacturing industry, where companies procure numerous parts and services from suppliers, cyber security must be guaranteed along the entire supply chain. Suppliers who deliver critical components or software pose a particularly high risk if their systems are not adequately secured. The NIS2 directive therefore requires companies to regularly check their suppliers for security risks and ensure that they meet the specified standards.

A crucial aspect of implementing these requirements is the risk-based consideration of suppliers. Not every supplier poses the same risk. A supplier that supplies the canteen, for example, has less influence on the company's security situation than a supplier that supplies control units for production facilities. It therefore makes sense not to design the inspection processes for all suppliers with the same intensity, but to prioritise them according to their criticality. This helps to minimise the effort and deploy resources specifically where the risk is highest.

Verification and documentation of security measures  

Another important point in ensuring supply chain security is the verification of the security measures taken by suppliers. It is not enough for a supplier to simply submit a specification sheet with security requirements. Rather, these requirements must be backed up by concrete measures and evidence. This can be done through tests or audits that confirm the effectiveness of the implemented security measures.

These tests should not be carried out once, but should be repeated regularly. Suppliers who have privileged access rights to critical systems, such as system integrators or maintenance providers, should be checked particularly intensively.  

ISO 27001 and other standards: The basis for supply chain security 

ISO 27001 certification is often used as an indicator of good risk management and a high level of cybersecurity in companies. A supplier that is ISO 27001 certified shows that it is working systematically and continuously on its cyber security. However, even ISO 27001 certification does not guarantee that all of a company's specific security requirements are met. It is therefore necessary to introduce further audit processes in addition to existing certificates such as ISO 27001 to ensure that the supply chain security requirements are actually met.

The challenge is to implement these processes in a practicable form. The introduction of these testing and verification processes is a major challenge, especially for smaller companies (SMEs). They often lack the necessary resources and a clear structure to regularly audit all suppliers and service providers.

Cyber resilience and the future of the EU economy 

The Cyber Resilience Act and the NIS2 Directive aim to strengthen cyber security in the EU in the long term and achieve greater resilience to cyber attacks. This is not just about the security of individual companies, but also about the economic sovereignty of the EU as a whole. In an increasingly networked global economy, cybersecurity is an important competitive factor. In the face of growing threats from cyberattacks, it is crucial that companies continuously improve their security measures and keep them up to date.

However, for many companies, especially SMEs, this can be overwhelming. The new regulatory requirements entail a great deal of organisational effort. However, the EU must find a way to implement these requirements in such a way that they do not place an excessive burden on companies.

Conclusion: A necessary step for the future

The new requirements of the Cyber Resilience Act and the NIS2 Directive present companies with a number of challenges. However, they also offer an opportunity to strengthen cyber security in the EU in the long term and to protect the economy against the growing threat of cybercrime. Establishing clear reporting obligations, verifying security measures in the supply chain, ensuring OT security and standardising processes are crucial steps that companies must take now to improve their security measures and be prepared for future requirements.

The introduction of robust security processes and collaboration throughout the supply chain will enable the resilience of the EU economy to be sustainably strengthened and contribute to global competitive advantage

.
Screen Shot 2025-05-15 at 18-ba6e.png

Annika Gamerad

Event & Marketing Specialist

Published on 15.05.2025