SUBSCRIBE NOW
IN THIS ISSUE
PIPELINE RESOURCES

The End of Ship and Forget:
EU Cyber Resilience Act and IoT



Strip away the regulatory language and the Cyber Resilience Act is describing what a well engineered connected product should have looked like all along...

The reporting rules make the point sharper. From September 2026, a manufacturer that learns of an actively exploited vulnerability in one of its products has twenty four hours to send an early warning to the European authorities through a single reporting platform run by the EU cybersecurity agency. A fuller notification follows within seventy two hours, and a final report within fourteen days. That is not a documentation task. That is an incident response capability. It assumes you already know what you shipped, you are already watching for problems, and you can move within a day when one appears. Most hardware companies have never had to operate that way. The ones that build the muscle now will not be improvising in a crisis later.

Not all of this is equally hard. The conformity assessment, the CE marking, the declaration of conformity, the technical file. All of that is real work, but it is the kind of work that consultancies and standards bodies are already lining up to help with. It is tractable. The genuinely hard part is the thing the paperwork stands in front of, which is an organization and a codebase that can still deliver a trustworthy fix to a device years after the sale. That capability cannot be bought at the end. It has to be built in from the architecture up.

For the communications industry this lands close to home. The whole sector runs on fleets of long lived, connected, deployed devices, and on deep supply chains where a finished product carries components and software from many hands. The regulation reaches through that supply chain. Whoever places the product on the market inherits responsibility for what is inside it, which changes how much you need to know about your suppliers and how you write your contracts with them. It rewards operators and vendors who already have visibility into their fleets and can update them cleanly, and it exposes the ones who cannot. The European Union is also not acting alone. Other governments are moving in the same direction, and a manufacturer that solves this properly for Europe will find it has largely solved it everywhere.

There is a way to read all of this as pure cost, and plenty of companies will. That reading is a mistake. Strip away the regulatory language and the Cyber Resilience Act is describing what a well engineered connected product should have looked like all along: a device you can see into, a device you can reach and fix, backed by an honest promise about how long it will be supported. Customers have wanted those properties for years even when they could not name them.

The teams that come through this well will be the ones that treat the support period as a feature to design for rather than a liability to minimize. If you decide up front that a product will be securely maintainable for its full expected life, that decision shapes the hardware you choose, the update path you build, the way you track what you ship, and the way you staff the years after launch. If that decision comes late, every part of it gets harder and more expensive. Make it early and most of the compliance work turns out to be a byproduct of having built the thing properly.

The work that matters between now and then is building products, and teams, that can keep a promise to a device for its entire working life. A binder can be assembled in a quarter. That promise cannot, and the deadlines are closer than they look. The reporting obligations are a little over a year out, and the full requirements follow the year after that.


FEATURED SPONSOR:

Latest Updates





Subscribe to our YouTube Channel