The Cyber Resilience Act and Software Supply Chains: Underestimated Risks for Defense Companies

Jaber Kakar, Head of Information Security

7. July 2026

Many companies in the defense industry are convinced that the Cyber Resilience Act affects them only to a limited extent. After all, the EU regulation includes an exemption for certain defense-related goods. But it is precisely this misconception that poses significant risks. The exemption applies much less frequently than many assume.

But it is precisely this assumption that can pose a risk. This is because the exception does not apply across the board to companies, entire product portfolios, or complex software supply chains. What matters is always the specific assessment of individual products, components, and use cases.

In this article, we explain what this means in practice, what regulatory, organizational, and operational risks it entails, and what defense companies should be paying attention to now.

In this post:

What the Exception for Defense Products in the CRA Actually Means

The Cyber Resilience Act (EU 2024/2847) includes an exemption for products with digital elements that were developed exclusively for defense or national security purposes. The reason: These products are already subject to specific security and defense regulations.

“Exclusively” is the key phrase. And it is meant in a narrow sense.

This is because the CRA exemption does not apply across the board to entire companies or complete product portfolios. It applies solely to specific products and use cases.

As soon as a product also has civilian applications, the exception generally no longer applies.

In practice, this creates some gray areas. Many defense companies today develop products that cannot be clearly classified under a single category of use:

  • Dual-use products that are used for both civilian and military purposes
  • Civilian versions of military systems
  • Software platforms with multiple areas of application
  • Commercial IT components that are also supplied to military customers
  • Products with open-source or third-party software

The CRA may be fully relevant to these areas.

For many companies, this is exactly where the real challenge begins.

The chart illustrates the dual-use gray areas related to the Cyber Resilience Act

The real challenge lies in product classification

For many companies, the CRA challenge begins with a fundamental question: Which of our products are actually covered by the Cyber Resilience Act—and which are not?

This assessment is often complex, particularly in the defense sector. Systems are further developed, receive new functions, or later find additional applications beyond their original intended use. What is developed today exclusively for military purposes may later exhibit characteristics of a dual-use product due to new functions, additional customer groups, or expanded application scenarios.

For this reason, product classification is not merely a technical or legal task. It must also take into account future changes in functions, application scenarios, and intended uses.

To do this, it is necessary to bring together every conceivable perspective: development, product management, compliance, information security, and the legal department. Only by taking a holistic view can we reliably assess which requirements apply and what documentation will be needed in the future.

The question is not just what a product was designed for today—but what it could be used for tomorrow.

But even once the product classification has been clarified, not all questions have been answered. After all, product classification is only the first step. The next step focuses on the question of which digital components a system actually consists of.

Why Software Supply Chains Are Particularly Relevant for Defense Companies

In the past, defense systems were largely developed as closed, in-house projects using components under the company’s own control. Modern defense solutions, on the other hand, consist of a multitude of digital components that often come from complex supply chains and various sources. In the future, companies will also need to more thoroughly assess and document the security capabilities of their suppliers. And this is precisely where a core problem lies.

Specifically, this applies to:

  • Embedded Software and Firmware in Systems
  • Open-source components and third-party libraries
  • Cloud services integrated into products
  • External development service providers and their code contributions
  • Software platforms with multiple applications

For many defense companies, this means that CRA relevance arises not only from the end product, but from the sum of all digital components. A system may be classified for military use as a whole—yet still contain civilian software components that trigger the CRA.

As a result, the focus of regulation is shifting: it is no longer just about the finished end product, but about all digital components throughout their entire lifecycle.

Responsibility for cybersecurity does not end at the company’s boundaries.

A woman sitting at a computer quickly pulls her hands away from the keyboard in surprise.

CRA compliance starts with the employees

A woman sitting at a computer quickly pulls her hands away from the keyboard in surprise.

Does a product or service fall under the Cyber Resilience Act? Good employees can plan for the CRA from the outset. We’d be happy to train your team in these skills.

What Defense Companies Should Know and Do Now

On September 11, 2026, the Cyber Resilience Act will take effect for the first time. As of that date, reporting requirements for actively exploited vulnerabilities and serious security incidents will apply. Violations can be punished with fines of up to 15 million euros or 2.5 percent of global annual revenue —whichever amount is higher.

The issues discussed so far regarding product classification, dual-use items, and software components serve merely as a foundation.

The CRA also requires companies to translate these findings into robust processes and lines of responsibility.

And that’s where the real challenge begins. Because the evaluation of products and components must lead to concrete processes. Four questions are central to this:

  • Ability to Provide Evidence: What documentation, risk analyses, and evidence must be provided to customers, auditors, and regulatory authorities?
  • Responsibilities: Who makes decisions and who is accountable in the areas of development, procurement, compliance, information security, and management?
  • Vulnerability Management: How are security vulnerabilities identified, assessed, documented, and addressed throughout the entire product lifecycle?
  • Reporting Processes: How are incidents identified, assessed, and reported within the specified timeframes?

It is precisely these organizational and procedural requirements that are underestimated in many companies. Yet this is what determines whether CRA compliance works in practice or exists only on paper.

Training sessions and hands-on exercises can help ensure that these requirements are implemented early on in the relevant departments.

CRA compliance is an organizational responsibility

The CRA does not merely require safe products. It also requires the ability to respond to safety incidents quickly, transparently, and in a documented manner.

Specifically, companies are required to,

  • to submit an initial report within 24 hours,
  • to submit a follow-up report with additional technical information within 72 hours,
  • to submit a final report upon completion of the analysis,
  • to be able to provide evidence of documented decision-making and reporting processes,
  • and define clear responsibilities.

To achieve this, the development, procurement, compliance, information security, and management departments must work together much more closely than they have in the past. In practice, organizations rarely fail because of a lack of technology, but much more often because of unclear processes, a lack of defined responsibilities, and a lack of coordination among the departments involved.

Practical exercises on incident response, reporting chains, and role-based responsibilities help identify and close these gaps early on, before a real security incident occurs.

A 24-hour reporting deadline leaves no room for unclear responsibilities.

Conclusion: The CRA exception is more limited than many people assume

The defense exemption under the Cyber Resilience Act is real—but it is significantly narrower than many companies assume. For most defense OEMs and their suppliers, software supply chains, development processes, and organizational responsibilities will be particularly relevant.

“The greatest danger is not that companies will be unable to meet the requirements of the Cyber Resilience Act. The greatest danger is that they will misjudge how much they are affected—and therefore wait to take action until time is already working against them.” – ML Gruppe

It will be crucial that the relevant departments understand the CRA’s requirements and can apply them correctly.

September 11, 2026, is not just an abstract deadline—it is a real-world test.

Companies that train their teams today will succeed.

Companies that wait will find that 24 hours go by very quickly.

Therefore, companies should use the time remaining before implementation to review product classifications, define responsibilities, and prepare the teams involved for their tasks.

Regulation (EU) 2024/2847 of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act). Official Journal of the European Union, October 23, 2024. https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX%3A32024R2847 European Commission: Cyber Resilience Act – Questions & Answers Federal Office for Information Security (BSI): Information on the Cyber Resilience Act ENISA – European Union Agency for Cybersecurity: Cybersecurity Supply Chain Guidance LUTZ | ABEL Rechtsanwaltsgesellschaft mbH: Cyber Resilience Act – Assessment of Dual-Use Issues and the Defense Exception (Art. 2, para. 7 CRA), March 2026. Bitkom e.V.: Guide to the Cyber Resilience Act for Manufacturers and Retailers, Berlin, 2025. https://www.bitkom.org

Ensuring CRA Compliance

The ML Gruppe supports companies in the defense industry with practical training programs on CRA compliance, incident response, and security by design—tailored to the industry’s specific requirements.

FAQs on the Pay Transparency Directive