ArmorCode Helps Manufacturers Prepare for EU Cyber Resilience Act

▼ Summary
– ArmorCode has added Cyber Resilience Act (CRA) capabilities to its Agentic AI Platform to help manufacturers of products with digital elements comply with the EU regulation.
– The EU Cyber Resilience Act, effective December 2024, requires manufacturers to remediate vulnerabilities without delay and imposes strict reporting deadlines starting September 11, 2026.
– Non-compliance penalties reach up to €15 million or 2.5% of global annual turnover, and most organizations currently lack a centralized system to meet reporting obligations.
– New platform features include exploit-aware risk prioritization, automated workflow orchestration for CRA deadlines, and continuous SBOM and VEX management.
– The platform integrates over 375 tools to unify security data into a single source of truth, enabling audit-ready compliance without replacing existing systems.
ArmorCode has introduced new capabilities tailored to the Cyber Resilience Act (CRA) within its ArmorCode Agentic AI Platform. These features are designed to assist manufacturers of products with digital elements (PDEs) in preparing for the European Union’s sweeping cybersecurity regulation, which will affect all sellers of such solutions operating in the region.
With this update, ArmorCode helps organizations operationalize CRA requirements through a unified system of record. This system integrates product security data, exploit-aware risk prioritization, disclosure workflow management, software bill of materials (SBOM) and vulnerability exploitability exchange (VEX) support, and continuous compliance reporting.
The EU Cyber Resilience Act, which took effect in December 2024, establishes strict cybersecurity standards for digital products sold within the European Union. It mandates that manufacturers remediate vulnerabilities without delay. Starting September 11, 2026, companies must meet rigorous reporting obligations for actively exploited vulnerabilities. These obligations include issuing a 24-hour early warning notification, a 72-hour vulnerability notification, and a final report within 14 days of a corrective or mitigating measure becoming available. Non-compliance carries penalties of up to €15 million or 2.5% of global annual turnover, whichever is higher.
Currently, most organizations struggle to operationalize these reporting demands. They lack a centralized system to manage the data, workflows, and evidence required. Critical information is scattered across vulnerability scanners, threat intelligence feeds, asset inventories, SBOM repositories, ticketing systems, and compliance platforms. This fragmentation creates operational complexity and heightens the risk of missing deadlines.
“The Cyber Resilience Act is redefining accountability for cybersecurity by extending focus beyond operators to the security capabilities of product suppliers,” said Larry Lowe, Chief Product Security Officer for Wabtec. “In anticipation, we proactively aligned our development processes with IEC 62443-4-1 and invested in scalable solutions to operationalize security. With ArmorCode, we are achieving the visibility and automation needed to consolidate vulnerability data, streamline disclosure workflows, and track risk in real time, enabling us to meet the pace and scale that the CRA demands while reinforcing customer trust.”
Mark Lambert, Chief Product Officer at ArmorCode, added: “The CRA turns product security into a reporting discipline with a deadline attached. The manufacturers who handle it well won’t build a separate compliance program for it, they’ll run it on the platform they already use to manage exposure. And as only actively exploited vulnerabilities start the 24-hour clock, knowing what’s actually being exploited is the difference between a workable process and a fire drill.”
The expanded ArmorCode Agentic AI Platform now supports key CRA workflows and requirements, including:
- Native PDE classification and lifecycle tracking for products and sub-products subject to CRA rules.ArmorCode helps teams focus on the most critical vulnerabilities by incorporating exploitability data into risk prioritization. Only vulnerabilities flagged as Actively Exploited trigger the 24-hour reporting clock, reducing noise while maintaining a complete audit trail.“Cyber resilience is a business requirement,” said Karthik Swarnam, Chief Security and Trust Officer at ArmorCode. “The Cyber Resilience Act raises the stakes for every organization that builds or sells digital products in Europe. Failing to identify and report actively exploited vulnerabilities can result in significant financial penalties, but the greater risk is the loss of customer trust and confidence. Organizations need a way to operationalize security, compliance, and disclosure at scale. ArmorCode helps teams bring together the data, workflows, and evidence needed to respond quickly, demonstrate accountability, and stay ahead of evolving regulatory requirements.”The CRA capabilities are built on the ArmorCode Agentic AI Platform, which consolidates security findings, asset intelligence, software supply chain data, threat intelligence, cloud security signals, and business context into a single source of truth. With more than 375 integrations, ArmorCode enables organizations to correlate findings, prioritize risk, automate remediation workflows, and generate audit-ready evidence without replacing existing security tools.
