ServiceNow’s Anna Mazzone discusses obligations of the Cyber Resilience Act and why more Irish software firms may be in scope than most realise.
The EU Cyber Resilience Act’s first deadline on 11 September activated Article 14’s reporting obligations for any Irish company that develops software, or has them developed and markets it under its own name.
This includes downloadable clients, mobile apps, embedded firmware, freemium software and any product connected to a device or network. The Act’s definition of ‘manufacturer’ is legal rather than descriptive, and the products it covers run across hardware and software.
The Act requires products to be secure by design, secure by default and secure throughout their life cycle. Anything short of that cannot be placed on the EU market. The reporting duty arrived first, more than a year ahead of the full technical requirements due in December 2027.
Under EU law, a manufacturer is any person or company that develops products with digital elements, or has them developed, and markets them under its own name or trademark, whether paid, monetised or free.
The qualifier is commercial activity. Software supplied outside a commercial activity, including free and open-source software that its maker does not monetise, falls outside the regulation.
Freemium and open-source components monetised by their original maker are inside it. A product with digital elements is a software or hardware product, together with the remote data processing it needs to function.
Read that against what Irish technology companies actually ship. The National Cyber Security Centre (NCSC) lists operating systems and mobile apps alongside laptops and industrial IoT in its description of in-scope products.
Standalone cloud services sit under separate rules. But when a cloud feature is integral to how the product functions, it becomes part of the product for CRA purposes.
There is no production‑line test. If you write software and put your name on it, you are in scope.
What applies now
Two things start the clock: an actively exploited vulnerability in one of your products, or a severe incident affecting that product’s security.
From the moment you become aware, you have 24 hours to file an early warning and 72 hours to follow it with a severity assessment. Both periods run from awareness, not from each other. Then the two triggers part ways. A vulnerability needs a final report within 14 days of a fix being available, which may be months later or never. An incident needs a final report within a month of the 72-hour filing.
Reports route through ENISA’s Single Reporting Platform to the national Computer Security Incident Response Team (CSIRT), which, for companies that take their product cybersecurity decisions in Ireland, is CSIRT‑IE inside the NCSC. The NCSC published guidelines on Article 14 reporting on 31 August and runs a CRA helpdesk, though it states plainly that it will not advise on whether a given product is in scope.
There is more than reporting to meet. The essential cybersecurity requirements mean protecting the product against unauthorised access, supporting and updating it for its stated lifetime and carrying CE marking.
Each member state designates its own market surveillance authorities, and they can require a product to be corrected, withdrawn or recalled. Fines are tiered. Articles 13 and 14 sit in the highest band alongside those requirements, at the higher of 2.5pc of total worldwide annual turnover from the preceding financial year or €15m. December 2027 is when the fines begin.
The Act also arrives ahead of Ireland’s own cybersecurity legislation.
The National Cyber Security Bill, which will transpose the NIS2 Directive, has not yet been published. The Government expects to notify transposition by the end of 2026. The Cyber Resilience Act is a regulation rather than a directive, so it applies directly and does not wait on national law.
Six practices that put you in a position to comply
Embed compliance in product development
Bring security risk assessments into the design stage and define the controls from there. Retrofitting them after a product ships costs more every time.
Track security markings and vendor commitments
Make sure suppliers give you the same assurances that your customers expect, and store those responses where the incident team can easily find them.
Even if a vulnerability comes from a component you didn’t develop, you’re still responsible. The NCSC named supply chain security as one of three systemic risks in its 2025 National Cyber Risk Assessment and recommended strengthening procurement rules around security from the start.
Incorporate vulnerability management
Continuously check for vulnerabilities, share what you find with your customers and maintain a well‑defined, solid patching process. Article 14 tests this directly, because the 24‑hour clock starts regardless of whether or not a process is in place.
Govern access
Products need protection from unauthorised access through appropriate control mechanisms, including authentication, identity management and secure default configurations.
Test resilience regularly
Ongoing scenario, impact and tolerance testing validates secure life cycle management rather than leaving it on paper.
Maintain a software bill of materials (SBOM)
Document and provide a full inventory of components with each product you sell. The Open Source Security Foundation found in June that only 32pc of manufacturers produce an SBOM for every product they ship.
What you gain
The payoff shows up the first time a report lands. Knowing what is inside what you ship turns ‘is that component in a live product’ from a week of investigation into a few minutes.
A single incident record means the 72-hour notification builds on the 24-hour one rather than starting again. Supplier exposure you can already see is one fewer thing to chase on the day. And a named decision-maker with real authority means you never spend the clock waiting for a call to go up three levels and come back. This last one is what most often causes companies to miss the deadline.
That work pays back beyond the regulator. Customers now ask for an SBOM and a vulnerability disclosure policy during procurement and read the answer as a signal of whether you are a safe supplier.
The Act asks software companies to demonstrate something most already tell customers they do. Since 11 September, the claim is checkable.
By Anna Mazzone
Anna Mazzone is VP of EMEA Operational Resilience, Risk and Security at ServiceNow and non-executive director at the Global Legal Entity Identifier Foundation. In 2013, she founded the first managed KYC shared services for global capital markets at Thomson Reuters. In 2016, Anna was named on Innovate Finance’s ‘Women in Fintech Powerlist’.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
You must be logged in to post a comment Login