The Cyber Resilience Act introduces horizontal cybersecurity requirements for products with digital elements marketed in the European Union.
It is relevant for manufacturers, developers, integrators and companies that distribute software, connected devices or digital components.
Security is no longer just a good practice: it becomes part of the product life cycle, documentation and vulnerability management.
What a company should review
- Security by design and by default.
- Vulnerability management during the life cycle.
- Technical documentation and manufacturer's obligations.
- Coordination with secure development, AppSec and supplier management.
How we work at Blue Moon
The practical recommendation is not to approach each standard as an isolated folder. ISO 27001, ENS, NIS2, DORA, data protection and secure development share assets, risks, controls, suppliers, incidents and evidence.
We can review whether this rule affects your company and turn it into a clear, prioritized and acceptable roadmap.
Request diagnosis →