Spectra Assure Free Trial
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free TrialSeptember is when mandatory incident-reporting obligations for vendors take effect. If a vulnerability is actively exploited, manufacturers must notify both regulators and affected customers. That will require a big adjustment, since many organizations still struggle with basic visibility into vulnerabilities and incidents, let alone coordinated disclosure.
Much of what the CRA seeks to enforce are things that have long been inconsistently applied: timely detection, clear communication, and accountability across the software lifecycle.
One of the most significant aspects of the CRA is its scope.
The regulation applies to “products with digital elements,” a deliberately broad definition that includes software, firmware, and connected devices. “It’s written for manufacturers, resellers, distributors of products with a digital component, … which is every product,” van der Hout said.
This expansive scope ensures that the CRA will reach far beyond traditional software vendors. Any organization placing digital products on the EU market — whether a SaaS provider, a device manufacturer, or a software publisher — will fall under its requirements.
At its core, the CRA enforces principles that have long been advocated but have been unevenly implemented.
Configurations that are secure by design and secure by default, often dismissed as buzzwords, are no longer optional under the CRA; they are regulatory requirements.
“You need to have certain standards and certain baseline rules apply to your products.”
—Madelein van der Hout
Any organization with legacy products will face the challenge of retrofitting security controls, which is significantly more expensive than building them in from the start.
Despite the CRA’s broad reach, many organizations assume that compliance is primarily a problem for vendors. While it’s true that manufacturers face regulatory penalties, said van der Hout, organizations that deploy software remain accountable for managing their own risk. That includes understanding dependencies, assessing exposure, and responding to incidents.
This aligns with a shift already underway in software supply chain security: shared responsibility across producers and consumers. ReversingLabs research shows that many organizations are struggling with this model, mainly because they lack the tools to fully assess the integrity of third-party software or detect tampering in delivered code.
The CRA raises the stakes by turning those gaps into compliance risks with serious, financial penalties for non-compliance.
While the CRA is a law governing EU businesses, it is likely to reshape the global software market, van der Hout said.
Like the GDPR before it, the CRA will extend beyond Europe. Global companies that want access to the EU market will need to comply. And once those practices are in place, they are likely to become the default worldwide.
That makes the CRA more than a regional regulation; it’s a catalyst for change in how software is built, secured, and trusted. The organizations that act early will have an advantage. Those that wait may find themselves scrambling — not just to comply, but to keep up.
Still, that may not include many small- and early-stage vendors who decide to stay out of Europe as a way to skip CRA compliance.
“It’s not always plausible that [startups] are able to comply with that regulation because it costs a lot of money.”
—Madelein van der Hout
That will affect EU organizations that rely on those vendors, costing them critical suppliers, forcing them into product replacements, and potentially placing them in compliance violations. “What if you rely … completely on these products? You have a huge problem,” van der Hout said.
This introduces a new dimension of supply chain risk: vendor attrition driven by regulation.
As complex and costly as the CRA is, however, van der Hout said, it’s also necessary — and overdue. “I do believe it’s the missing piece of the puzzle,” she said.
To explain why, she drew an analogy to early automotive history. When cars first appeared, they shared roads with horse-drawn carriages — but without rules. The result was chaos. Over time, regulations introduced structure and safety.
For van der Hout, cybersecurity regulation serves a similar purpose:
“For me, cybersecurity regulation — those are brakes.”
In other words, the CRA is not just about compliance; it’s about creating a baseline of trust in digital products.
For van der Hout, organizational readiness for the CRA echoes that for the rollout of the GDPR, when many organizations delayed action until the final months, triggering a scramble for compliance that strained vendors and customers alike.
“We always start too late,” she said. “All of a sudden the compliance date is around the corner, but we’re so not prepared.”
But, unlike GDPR, the CRA carries broader technical and operational implications tied directly to software development and security practices, van der Hout said.
The message for organizations is clear: waiting is not an option. To prepare for the CRA, companies should prioritize:
These steps are not just about regulatory alignment — they address the same gaps that attackers are already exploiting.
In the end, van der Hout sees the CRA as an enabler of technology and innovation. A big fan of car racing, she recalls the America racing icon Mario Andretti’s quote that brakes are “for going faster” — giving cars the precision and control needed to navigate at high speeds. The same concept applies to software, van der Hout said.
“I thoroughly believe that is also how we should approach cybersecurity regulation. It should not just be your competitive advantage — it should be your accelerator.”



The annual cybersecurity conference focused on frontier AI agents — and what they mean for cyber. Here are three key takeaways.

Researchers built a worm that reasons about hosts it infects, and the open-weight models powering it sit outside AI-provider safety controls.

While prompt injection and data disclosure remain concerns, excessive agency climbed the list — not surprising with recent security incidents.