Contact
← Retour au blog
Expertise07/04/2025

The Cyber Resilience Act: what impact on contract management?

The Cyber Resilience Act (or CRA) is a European regulation that forms part of the European Union's adoption of a legislative framework addressing the cyber threat.…

Pierre MarchèsPartner · fondateur
The Cyber Resilience Act: what impact on contract management?

The Cyber Resilience Act (or CRA) is a European regulation that forms part of the European Union's adoption of a legislative framework addressing the cyber threat. That framework, already made up of directives (see the NIS 2 directive, or the directive on the Resilience of Critical Entities, "CER") and of regulations (see in particular DORA, or the regulations on AI and on Data), is now reinforced by the CRA.

A. The Cyber Resilience Act in brief

i. When does it come into force?

The CRA came into force on 10 December 2025. Companies have until 11 December 2027 to comply, except for:

  • The reporting obligations falling on manufacturers, which must be effective from 11 September 2026;
  • The notification of conformity assessment bodies, which must be carried out from 11 June 2026.

ii. What is the scope?

All economic operators involved in placing products with digital elements on the market and in their lifecycle, in particular the following categories:

  • Manufacturers of such products (whether they are placed on the market for consideration or not)
  • Software publishers
  • Importers of such products into the European market, where the manufacturer is established outside the EU
  • Distributors who make the products available on the European market.

As regards products, it should be noted that the CRA provides for a number of exclusions, in particular:

  • Cloud and SaaS services (already covered by NIS 2);
  • Medical devices, aeronautical products and, more generally, any product already subject to specific regulation in this area.

Like many American and European texts, the CRA has extraterritorial reach. This means that the operators concerned, whether or not they are based in the EU, will have to comply with the CRA if they wish to place their products on the European market.

iii. Which product categories?

The CRA classifies products with digital elements ("PDEs") according to their level of criticality. In ascending order of criticality, these are:

  1. So-called "simple" PDEs;
  2. Free and open-source software;
  3. Class 1 and class 2 PDEs;
  4. So-called "critical" PDEs.

A great many products are therefore concerned: cameras, software, drones, connected objects, and also automation systems and other operating systems or platforms managing large installations.

iv. What obligations?

The obligations applying to the economic operators concerned vary according to the criticality of the products. A degree of latitude is left for the products in chapters 1 and 2 (see previous paragraph), since checks may be carried out internally or through external bodies.

On top of these checks, cybersecurity requirements must be taken into account whatever the classification of the products. These requirements relate both to the products themselves, which must be free of known vulnerabilities and include features allowing those vulnerabilities to be monitored, and to vulnerability management, since operators must put in place mechanisms to notify and raise the alarm in the event of a vulnerability or an incident.

In substance, the CRA sets out three levels of obligation:

  • Taking cybersecurity into account from the design stage of the product (cybersecurity by design). In practice this can mean encrypting data, banning weak passwords, or automating security updates.
  • Managing vulnerabilities throughout the product lifecycle, including transparency towards consumers and continuous compliance.
  • Monitoring, with control mechanisms, risk assessment and, where appropriate, obtaining certifications.

Finally, it is important to note that the CRA operates alongside the other regulations and directives (see the introduction to this article) and therefore does not list exhaustively the obligations that the economic operators concerned must comply with.

v. What penalties?

The penalties provided for can reach €15m or 2.5% of total annual turnover (whichever is higher). In addition, a product that is non-compliant or that the market surveillance authority considers to present a risk may be subject to restrictions going as far as complete withdrawal from the market!

B. The impact of the Cyber Resilience Act on contract management

After NIS2, which targeted networks and information systems and therefore OESs (operators of essential services) and DSPs (digital service providers), the CRA now takes on the product value chain, with consequences for contract management practice!

i. Taking stock

The first consequence, and not the least, is to take stock: which products are concerned? Which parts of my organisation's value chain are likely to be affected?

Once that initial stocktake has been carried out, contract portfolios will need to be analysed in order to establish whether or not there are provisions offering, depending on the case, either flexibility or a warranty that the products comply with current and future laws and regulations.

The question will also arise of product components containing open-source software, which is also subject to the CRA, and more broadly of categorising products by criticality (see paragraph a.iii above).

In short, a whole set of questions to ask during this stocktaking phase, which will vary greatly depending on your business model.

ii. Adding dedicated clauses

Both customer contracts and supplier contracts will see their content affected by the entry into force of the CRA.

On the customer side, the aim will be to draft new clauses limiting exposure to risk, particularly for innovative products or solutions that may require an exploratory phase. Clauses precisely defining the documentation and deliverables to be provided will be welcome, not least in anticipation of the documentary and regulatory inflation that comes with demonstrating CRA compliance.

On the supplier side, by contrast, care should be taken to insert clauses guaranteeing CRA compliance, allowing information to be shared and audits to be carried out. Specific clauses on incident management procedures, or on cybersecurity insurance cover, may also be welcome.

iii. Contract management & administration

Finally, beyond drafting the contract, specific contract management actions can also be put in place to ensure that contracts are properly performed and that the obligations arising from the entry into force of this Cyber Resilience Act are met.

These actions may affect the supply chain, with updated supplier control procedures, a review of supplier selection criteria, or simulated attacks to assess not only how far "cyber by design" development and maintenance principles have been embedded, but also the transparency and reporting mechanisms triggered when vulnerabilities are detected.

On the customer commitments side, the contract manager will make sure that the undertakings given on documentation, but also on reporting and vulnerability disclosure, are properly followed. Particular attention may also be paid to interfaces, especially where other work packages or suppliers have to provide input data, in which case the contract manager will need to track any failure to supply data, or any late, incomplete or incorrect supply, which may give rise to relief or extensions of time. From there to saying that the CRA can be a source of opportunities for the contract manager is only a small step!

Expertise
L'auteur
Pierre Marchès

Fondateur de Prime Conseil, Pierre pratique le contract management depuis quinze ans, au sein de grands groupes comme d'ETI, ainsi qu'auprès de collectivités et de ministères français et étrangers. Il est spécialisé dans l'énergie, l'infrastructure et la défense.

Suivre Pierre sur LinkedInLire les 92 articles de Pierre
Le blog

Nos derniers articles.

Voir tous les articles
Staffing31/08/2026
Contract managers: 5 reads to prepare for the new season
Five reads to strengthen the contract manager's skills: improving contract management practice, negotiation, project management, communication and emotional intelligence.
Lire l'article →
Claims21/08/2026
Claim management: neither litigation nor expert analysis
Does claim management belong to the project, to procurement, or to contract management? The profession doesn't speak with one voice, and this confusion costs projects dearly. Definition, boundaries with litigation and expert analysis, and the division of roles: an article to set out the scope of a discipline of orchestration.
Lire l'article →
Processus17/08/2026
Contract memo: content and best practices
The contract memo is the first deliverable expected of a contract manager when they start on a project. Method, pitfalls to avoid and best practices from the field.
Lire l'article →

Let's get to know each other.

By email
contact@primeconseil.com
For the shy ones.
In person
1192, Bd Jean Baptiste Abel, 83000 Toulon38, Rue Jean Bouchet, 86000 Poitiers3 Bis, Rue Taylor, 75010 Paris
For the coffee lovers.
By phone
(+33) 04 12 33 31 01
For the straight talkers.
Emailcontact@primeconseil.comFor the shy ones.Phone(+33) 04 12 33 31 01For the straight talkers.
In person1192, Bd Jean Baptiste Abel, 83000 Toulon38, Rue Jean Bouchet, 86000 Poitiers3 Bis, Rue Taylor, 75010 Paris