Miguel Morales

Miguel Morales

Vice President, Cloud Alliances

Get in touch with Miguel Morales

Tell us briefly what it is about – we will pass your message on and make the introduction personally.

Podcast Episodes

#222
#222

Cyber Resilience Act for OEMs: From Compliance Evidence to a Lifecycle Service

The CRA comes with two dates: from September 2026, manufacturers have 24 hours to report actively exploited vulnerabilities and severe incidents; from December 2027, full conformity applies. Morales draws the line between the two regulations – the CRA governs manufacturers and their products, NIS2 the operators, with personal liability attached. That intersection is where his argument sits. CRA obligations stop at disclosing vulnerabilities and making patches available, and the patches must be free. Operators, though, have to prove their own compliance across equipment from many vendors. A manufacturer who hands them that evidence automatically is selling a lifecycle service, not just hardware. A published cybersecurity paper from Danfoss serves as the reference point. Beyond that, the conversation stays technical: SBOM generation, continuous firmware scanning, PKI certificates and update rollouts across globally distributed fleets. Morales calls the manual effort behind this the governance tax, and closes with ten actions for manufacturers. What you take away The first deadline is September 2026, not December 2027: 24-hour reporting for actively exploited vulnerabilities starts then. CRA and NIS2 interlock – the manufacturer’s obligation is the basis of the operator’s own proof. The patch must be free under the regulation; what can be priced is the rollout orchestration and the auditable evidence. Compliance shifts from an annual reporting exercise to a status calculated continuously from device state data. First of Morales’ ten actions: move CRA ownership out of legal and into the product P&Ls.

Aug 26, 2026