Finite State issues CRA cyber-security warning

Companies need to prepare for the first major enforcement milestone of the EU’s Cyber Resilience Act (CRA) coming in September, warns Finite State.

Cyber-security experts, OEMs, software publishers and end user organisations have focused on the CRA’s ultimate December 2027 compliance deadline for years. What’s received far less attention is the first major enforcement milestone on 11 September 2026, now less than 100 days away.

On that date, anyone selling connected products and applications into the EU must report actively exploited vulnerabilities and significant security incidents to regulators under strict timelines, within 24 hours.

“For many companies, the challenge isn’t simply reporting, it’s determining within a few hours whether a vulnerability exists inside their products, whether it’s being actively exploited, and who might be affected,” said Doc McConnell, head of policy and compliance at Finite State (finitestate.io). “The biggest obstacle isn’t paperwork, it’s visibility. Many companies lack accurate software inventories across their product lines, and have limited insight into third-party components embedded in products. Even more lack an in-place internal decision process to meet that 24-hour reporting mandate. The CRA readiness gap persists across sectors: ICS, automotive, medical devices, consumer electronics, IoT, IT gear, mobile applications distributed to EU end users, embedded software and more. And are their legal and compliance departments ready to assess cyber resilience?”

McConnell said the September deadline could likely be more disruptive than many organisations realised.

Ryan McCurdy, vice president of Liquibase (www.liquibase.com), added: “The CRA turns cyber security from a best practice into a reporting obligation. That creates a simple test for software manufacturers: can you prove what changed, who changed it, when it changed and whether the right controls were applied? For many organisations, the database layer is where that proof breaks down. Manual scripts, schema drift and inconsistent approvals make it hard to show control when regulators, customers or auditors ask. The companies that are ready for CRA will not just have security policies, they will have governance and proof of control across the full software lifecycle, including database change.”