#222 | Cyber Resilience Act for OEMs: From Compliance Evidence to a Lifecycle Service | Cumulocity episode artwork

EPISODE · Aug 26, 2026 · 49 MIN

#222 | Cyber Resilience Act for OEMs: From Compliance Evidence to a Lifecycle Service | Cumulocity

from IoT Use Case Podcast

www.iotusecase.com#CyberResilienceAct #CRA #NIS2How does a legal reporting duty turn into a service you can charge for? That is the question behind “Cyber Resilience Act for OEMs: From Compliance Evidence to a Lifecycle Service” on the IoT Use Case Podcast. Host Ing. Madeleine Mickeleit talks to Miguel Morales, Vice President Strategic Cloud Alliances at Cumulocity, about what the CRA asks of connected-product manufacturers and where it meets NIS2.Podcast SummaryThe CRA comes with two dates: from September 2026, manufacturers have 24 hours to report actively exploited vulnerabilities and severe incidents; from December 2027, full conformity applies. Morales draws the line between the two regulations – the CRA governs manufacturers and their products, NIS2 the operators, with personal liability attached.That intersection is where his argument sits. CRA obligations stop at disclosing vulnerabilities and making patches available, and the patches must be free. Operators, though, have to prove their own compliance across equipment from many vendors. A manufacturer who hands them that evidence automatically is selling a lifecycle service, not just hardware.A published cybersecurity paper from Danfoss serves as the reference point. Beyond that, the conversation stays technical: SBOM generation, continuous firmware scanning, PKI certificates and update rollouts across globally distributed fleets. Morales calls the manual effort behind this the governance tax, and closes with ten actions for manufacturers.What you take awayThe first deadline is September 2026, not December 2027: 24-hour reporting for actively exploited vulnerabilities starts then.CRA and NIS2 interlock – the manufacturer’s obligation is the basis of the operator’s own proof.The patch must be free under the regulation; what can be priced is the rollout orchestration and the auditable evidence.Compliance shifts from an annual reporting exercise to a status calculated continuously from device state data.First of Morales’ ten actions: move CRA ownership out of legal and into the product P&Ls.-----Relevante Folgenlinks:Madeleine (https://www.linkedin.com/in/madeleine-mickeleit-mrs-iot/)Miguel (https://www.linkedin.com/in/moralesamiguel/)CRA and NIS2 compliance (https://www.cumulocity.com/resource-library/cumulocity-eu-regulation-white-paper/)Cumulocity and EY Law (https://www.cumulocity.com/resource-library/building-cyber-resilience-for-the-eu-market/)Jetzt IoT Use Case auf LinkedIn folgen1x monatlich IoT Use Case Update erhalten

Episode metadata supplied by the publisher feed · Published Aug 26, 2026

Embed this episode

NOW PLAYING

#222 | Cyber Resilience Act for OEMs: From Compliance Evidence to a Lifecycle Service | Cumulocity

0:00 49:55

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of IoT Use Case Podcast?

This episode is 49 minutes long.

When was this IoT Use Case Podcast episode published?

This episode was published on August 26, 2026.

Can I download this IoT Use Case Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!