Urgent.News

What's breaking now, across thousands of outlets.

Business

What Irish tech companies need to know about the EU’s CRA

ServiceNow’s Anna Mazzone discusses obligations of the Cyber Resilience Act and why more Irish software firms may be in scope than most realise. Read more: What Irish tech companies need to know about the EU’s CRA

What Irish tech companies need to know about the EU’s CRA

The EU's Cyber Resilience Act (CRA) introduces obligations for Irish tech companies developing or marketing software with digital elements. The Act's first deadline, on September 11th, activated reporting requirements for any Irish company in scope, regardless of product monetisation. Products must be secure by design, default, and throughout their lifecycle.

Companies must act swiftly upon discovering vulnerabilities or incidents, notifying the relevant national CSIRT within 24 and 72 hours, respectively. Reports are filed through the ENISA Single Reporting Platform. Non-compliance may result in fines ranging from 2.5% of yearly turnover to €15 million. Companies must incorporate security risk assessments from the outset and ensure suppliers provide comparable assurances.

Continuous vulnerability checks, SBOMs, and clear vulnerability disclosure policies are essential. The CRA applies directly, superseding Ireland's own cybersecurity legislation, and poses significant risks for companies failing to comply.

Written by urgent.news from Silicon Republic's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at siliconrepublic.com →

More in Business

More from Tuesday 29 September →