What Irish tech companies need to know about the EU’s CRA
ServiceNow’s Anna Mazzone discusses obligations of the Cyber Resilience Act and why more Irish software firms may be in scope than most realise. Read more: What Irish tech companies need to know about the EU’s CRA
The EU's Cyber Resilience Act (CRA) introduces obligations for Irish tech companies developing or marketing software with digital elements. The Act's first deadline, on September 11th, activated reporting requirements for any Irish company in scope, regardless of product monetisation. Products must be secure by design, default, and throughout their lifecycle.
Companies must act swiftly upon discovering vulnerabilities or incidents, notifying the relevant national CSIRT within 24 and 72 hours, respectively. Reports are filed through the ENISA Single Reporting Platform. Non-compliance may result in fines ranging from 2.5% of yearly turnover to €15 million. Companies must incorporate security risk assessments from the outset and ensure suppliers provide comparable assurances.
Continuous vulnerability checks, SBOMs, and clear vulnerability disclosure policies are essential. The CRA applies directly, superseding Ireland's own cybersecurity legislation, and poses significant risks for companies failing to comply.
Written by urgent.news from Silicon Republic's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.