This blog is the 8th of our Tales From the Trenches: CRA Lessons Learned blog series. Our objective in developing these blogs is to help manufacturers, software vendors, and connected-product providers understand practical implementation realities of CRA compliance programs. We will draw on lessons we have learned from working with our customers and in talking to industry leaders.  Organizations are learning that sustainable compliance requires governance, visibility, accountability, and lifecycle management capabilities that extend well beyond traditional cybersecurity activities. Building a secure product is not enough to achieve CRA compliance.

 

Why Third-Party Readiness Is Emerging as a Critical Success Factor Under the Cyber Resilience Act

For many manufacturers and software vendors, Cyber Resilience Act (CRA) readiness efforts initially focus on internal activities. Organizations inventory products, perform risk assessments, implement vulnerability management processes, develop Software Bills of Materials (SBOMs), and establish governance frameworks designed to satisfy regulatory requirements.

These are all essential activities.  However, companies are discovering the internally focused activities alone are not sufficient.

Your compliance posture may depend as much on your suppliers as it does on your own organization.

Modern products are rarely built entirely in-house. They depend on complex ecosystems of component manufacturers, software suppliers, cloud service providers, contract developers, OEM partners, systems integrators, and open-source communities.  Each of these is a potential compliance risk.

A supplier that cannot provide software component information, support vulnerability investigations, maintain security updates, respond to evidence requests, or participate in coordinated disclosure processes can create significant challenges for downstream manufacturers attempting to satisfy CRA obligations.

This is causing organizations to rethink their view of supplier relationships.

What was once primarily a procurement concern is rapidly becoming a cybersecurity, compliance, and governance concern. As CRA enforcement dates approach, many organizations are discovering that supplier readiness may be one of the most important factors separating successful compliance programs from struggling ones.

Executive Insights

Historically, supplier management focused on issues such as cost, quality, delivery schedules, manufacturing capacity, and service levels. Cybersecurity requirements were often limited to contractual language, security questionnaires, or periodic assessments.

The CRA changes this equation. Organizations are now accountable for understanding the cybersecurity posture of products placed on the market, even when critical technologies originate from third parties.

Companies are beginning to ask new questions about their suppliers:

  • Can our suppliers provide current SBOMs?
  • How quickly can suppliers notify us of vulnerabilities?
  • Do suppliers maintain secure development processes?
  • Can suppliers support incident investigations?
  • Will suppliers provide compliance evidence when requested?
  • Can suppliers meet long-term support commitments?
  • What happens if a supplier discontinues a critical component?

These questions directly impact an organization’s ability to satisfy obligations related to vulnerability management, incident reporting, technical documentation, software transparency, product lifecycle support, and regulatory inquiries. All of which are critical requirements under the CRA.

Supplier governance is becoming a strategic business issue rather than a procurement activity. Organizations are increasingly recognizing that supplier cybersecurity maturity directly affects regulatory risk, customer trust, and operational resilience.

Why Supplier Risk Is Growing Under the CRA

Several factors are contributing to the growing importance of supplier readiness.

Products Depend on Complex Supply Chains

Today’s connected products often include embedded processors, operating systems, open-source software, third-party libraries, cloud services, communications modules, and security components.

Organizations frequently depend on hundreds of suppliers to support a single product.  This number grows substantially for companies with large, diverse product portfolios. The larger the ecosystem, the greater the compliance challenge.

Visibility Stops at Supplier Boundaries

Organizations are finding it challenging to manage and monitor their own development processes.  Visibility into cybersecurity compliance often decreases significantly when third-party technologies are involved.  Without supplier transparency, manufacturers struggle to answer critical compliance questions.

Vulnerabilities Travel Through Supply Chains

A vulnerability discovered in a supplier-provided component can rapidly impact multiple products. When a vulnerability is reported by a supplier, organizations must be able to determine which products are affected, which customers may be impacted, what remediation options exist, and whether regulatory reporting obligations apply.

This requires accurate and timely information from suppliers.

Lifecycle Accountability Extends Beyond Product Release

The CRA emphasizes ongoing support and vulnerability management requiring organization to manage cybersecurity and compliance for products for years after release.  Companies then, in turn, impose these requirements on their suppliers. In many cases, these suppliers are not yet up to the task.

Real-World Challenges

Managing vulnerabilities from third-party software components has always been a challenge for OEMs. With the CRA, this challenge is not just a security concern, but a compliance risk. When a critical vulnerability is disclosed in a third-party software component, OEMs using the component will immediately contact the supplier seeking clarification. If the supplier cannot quickly identify affected versions or provide remediation guidance, OEMs are blocked and unable to plan a response. Days can be lost while information is gathered. The issue is not the manufacturer’s response capability, it is the supplier’s lack of preparedness.

Product manufacturers may also struggle when asked to demonstrate software component visibility as part of a CRA readiness review.  The manufacturers rely on suppliers to provide complete SBOMs for components integrated into the product.  But many suppliers are not yet prepared to provide complete SBOMs and supporting documentation to allow manufacturers to develop a complete understanding of software dependencies. This creates a compliance challenge that originates outside the organization.

OEMs also struggle to adapt when a technology supplier unexpectedly discontinues support for a critical software component. In many cases, the unsupported component remains embedded in several actively supported products.  Remediation efforts become expensive and disruptive, requiring significant reengineering efforts to replace the component.  While the component may still perform the required function, the lack of support creates compliance risk. The risk emerged not from a vulnerability, but from supplier lifecycle decisions.

Best Practices for Supplier Governance Under the CRA

Organizations successfully addressing supplier risk are adopting several common strategies.

Establish Cybersecurity Requirements for Suppliers

Organizations should clearly define expectations regarding vulnerability disclosures, SBOM availability, security updates, incident notifications, and compliance evidence. Requirements should be incorporated into supplier agreements whenever possible.

Create Supplier Risk-Tiering Models

Not all suppliers carry the same level of risk.  Organizations should classify suppliers based on product criticality, security impact, software dependency levels, and regulatory relevance.  Higher-risk suppliers should receive increased oversight.

Assess Supplier Readiness Regularly

Supplier cybersecurity capabilities should be evaluated periodically rather than only during onboarding. Areas of focus should include vulnerability management, secure development practices, incident response processes, documentation quality, and lifecycle support commitments. These reviews should also include handing of any discovered or reported vulnerabilities or cyber incidents.

Improve Software Supply Chain Visibility

Organizations should maintain visibility into their use of supplier-provided components. This should encompass software dependencies, version information, and support status. Visibility is the foundation of effective governance.

Plan for Supplier Disruptions

Organizations should establish contingency plans for disruptions to suppliers’ business. These can result from supplier acquisition, business failure, product discontinuation, or support termination. These plans increase resilience and reduce long-term risk.

Common Pitfalls

Many organizations encounter similar supplier-related challenges.

Assuming Suppliers Are CRA-Ready

Many suppliers are still developing their own compliance programs. Some have not yet even started.  Companies must validate their supplier’s readiness rather than assume it.

Focusing Only on Tier-One Suppliers

Critical risks often originate deeper within the supply chain. Organizations should evaluate indirect dependencies where possible. For example, a communication module used in a connected IoT device has its own supply chain dependencies. The module may include hardware IP licensed from one or more hardware vendors, software developed in-house by the module vendor and licensed software components.  Supply chain visibility must extend through the full list of suppliers and sub-suppliers.

Treating Supplier Assessments as Procurement Exercises

Supplier capabilities, products, and support commitments evolve over time.  Companies must implement periodic reassessment schedules.

Overlooking Open-Source Dependencies

Open-source components embedded within supplier solutions can introduce additional visibility and governance challenges and must not be overlooked. We will cover this topic in more detail in our next blog post.

Action Items for OEMs and Software Vendors

Organizations seeking to strengthen supplier readiness should consider the following actions.

Immediate Priorities

  1. Inventory critical suppliers and software dependencies.
  2. Identify suppliers supporting products subject to CRA requirements.
  3. Assess supplier cybersecurity maturity.
  4. Review supplier vulnerability disclosure processes.
  5. Evaluate supplier SBOM availability and quality.
  6. Document supplier support commitments.
  7. Create security compliance requirements for vendors, and review supplier contractual requirements relative to these requirements.
  8. Establish escalation procedures for supplier-related security events.

Organizations that begin these efforts early will significantly reduce future compliance and operational risks.

How OmniTrust Certify Can Help

Managing supplier-related compliance obligations can quickly become overwhelming, particularly for organizations with large product portfolios and complex software and component supply chains. OmniTrust Certify helps organizations understand how third-party dependencies affect individual products, their cybersecurity risk, and their regulatory conformity.

Certify enables manufacturers and software vendors to:

  • Build a living product profile incorporating supplier components, software, firmware, and dependencies
  • Create or ingest SBOMs and identify third-party software dependencies
  • Connect suppliers and components to the products in which they are used
  • Identify vulnerabilities and cyber risks associated with third-party components
  • Maintain supplier-provided security, compliance, and lifecycle evidence
  • Assess the impact of supplier risks against applicable regulations and standards, including the CRA
  • Create traceability between suppliers, components, vulnerabilities, risks, controls, requirements, and evidence
  • Reassess affected products as supplier components, vulnerabilities, support status, or regulatory requirements change

By connecting supplier dependencies to the same living product record used for cyber risk and regulatory conformity, Certify helps organizations understand not simply whether a supplier presents risk, but which products are affected, what that means for compliance, and what action needs to be taken.

Summary

A critical lesson emerging from early CRA implementation efforts is that compliance is no longer confined within organizational boundaries. Your ability to demonstrate conformity may ultimately depend on the organizations that provide software, components, technologies, and services used within your products.

Manufacturers and software vendors that succeed under the CRA will need to extend cybersecurity governance beyond their own walls and across the broader product supply chain. Because in today’s connected world, your suppliers may become your biggest compliance risk.