Secure-by-Design: The EU Cyber Resilience Act
EU Cyber Resilience
SAP's Commitment to
Act (CRA)
Supporting your continued compliance – wherever regulations
take you next
CRA Compliance | SAP Solutions
© 2026 SAP SE or an SAP affiliate company. All rights reserved.
See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.
SAP's Commitment to
Act (CRA)
Supporting your continued compliance – wherever regulations
take you next
CRA Compliance | SAP Solutions
© 2026 SAP SE or an SAP affiliate company. All rights reserved.
See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.
Table of
contents
3 CRA strengthens the security of
digital products in the EU
4 How SAP is supporting your ongoing
CRA compliance
4 How SAP supports you — today and
tomorrow
5 Our commitment to cybersecurity
and partnership
contents
3 CRA strengthens the security of
digital products in the EU
4 How SAP is supporting your ongoing
CRA compliance
4 How SAP supports you — today and
tomorrow
5 Our commitment to cybersecurity
and partnership
CRA strengthens the security of digital products in the EU
A new baseline for secure-by-design technologies
The Cyber Resilience Act (CRA) is a major new EU regulation designed to improve the cybersecurity of products with digital elements. It aims to
ensure that specific hardware and software placed on the EU market meet consistent cybersecurity requirements across their lifecycle.
CRA represents a shift toward strong cybersecurity
built into digital products from the outset — helping
reduce risks and strengthening resilience across the
European digital ecosystem.Line arrow: Straight with solid fill
With obligations for manufacturers, importers, and distributors, CRA
introduces requirements for:
• Secure product design, development, and production.
• Vulnerability handling processes
• Transparency on cybersecurity features and proper use
• Reporting of actively exploited vulnerabilities and incidents
• Ongoing security support throughout product lifecycle
The CRA affects a wide range of digital products marketed or delivered
within the EU. As organizations modernize their techno logy landscapes,
the regulation reinforces:
What CRA means for SAP customers?
Helping you understand the new expectations
• The need for transparent security information
• Stronger vulnerability and patch management
• Consistent secure-by-design practices
• Clarity over supplier responsibilities
For SAP customers, CRA requires alignment with expectations
around transparency, secure dev elopment, and multi-layered
protection, as SAP has demonstrated with its existing offerings.
Thus, SAP’s compliance journey encompasses a harmonized
framework that complements the security posture customers
already expect from SAP’s solutions.
3| 6
A new baseline for secure-by-design technologies
The Cyber Resilience Act (CRA) is a major new EU regulation designed to improve the cybersecurity of products with digital elements. It aims to
ensure that specific hardware and software placed on the EU market meet consistent cybersecurity requirements across their lifecycle.
CRA represents a shift toward strong cybersecurity
built into digital products from the outset — helping
reduce risks and strengthening resilience across the
European digital ecosystem.Line arrow: Straight with solid fill
With obligations for manufacturers, importers, and distributors, CRA
introduces requirements for:
• Secure product design, development, and production.
• Vulnerability handling processes
• Transparency on cybersecurity features and proper use
• Reporting of actively exploited vulnerabilities and incidents
• Ongoing security support throughout product lifecycle
The CRA affects a wide range of digital products marketed or delivered
within the EU. As organizations modernize their techno logy landscapes,
the regulation reinforces:
What CRA means for SAP customers?
Helping you understand the new expectations
• The need for transparent security information
• Stronger vulnerability and patch management
• Consistent secure-by-design practices
• Clarity over supplier responsibilities
For SAP customers, CRA requires alignment with expectations
around transparency, secure dev elopment, and multi-layered
protection, as SAP has demonstrated with its existing offerings.
Thus, SAP’s compliance journey encompasses a harmonized
framework that complements the security posture customers
already expect from SAP’s solutions.
3| 6
4| 6
How SAP is supporting your ongoing CRA compliance
SAP has long embedded security into its engineering standards,
operations, and governance. Our approach aligns with many of the core
principles reflected in the CRA.
Secure development and responsible product stewardship
Strong executive governance of cybersecurity
Established secure development processesLine arrow: Straight with solid fill
• SAP’s cybersecurity strategy is shaped and supported by our Executive
Board.
• SAP Global Security & Compliance partners with engineering, cloud
operations, and product organizations to drive secure development and
continuous improvement.
Vulnerability handling and coordinated disclosure
• SAP maintains a mature global vulnerability management program,
supported by regular security patching, continuous monitoring, and
responsible disclosure practices.
• We publish monthly SAP Security Patch Day updates and provide
transparency into vulnerability remediation activities.
• SAP’s Secure Software Development and Operations Lifecycle (Secure
SDOL) includes threat modelling, code scanning, secure coding
standards, and continuous testing.
• These processes help ensure SAP products meet high security standards
throughout their lifecycle.
Lifecycle management and security maintenance
• SAP delivers software updates, security notes, and lifecycle support
policies that help customers maintain secure SAP environments over
time
Through these efforts, SAP supports customers who must meet
CRA-aligned policies within their own environments — offering
secure-by-design solutions without overpromising CRA-specific
guarantees.
How SAP supports you – today and tomorrow
A trusted partner for secure digital transformation
SAP solutions are designed with industry established security principles that form a solid foundation as regulatory expectations evolve. While SAP is not
offering CRA-specific consulting or tailored compliance products, our long-standing commitment to security, transparency, and responsible lifecycle
management helps support your organization’s resilience objectives.
We’re with you — wherever compliance takes you next...
How SAP is supporting your ongoing CRA compliance
SAP has long embedded security into its engineering standards,
operations, and governance. Our approach aligns with many of the core
principles reflected in the CRA.
Secure development and responsible product stewardship
Strong executive governance of cybersecurity
Established secure development processesLine arrow: Straight with solid fill
• SAP’s cybersecurity strategy is shaped and supported by our Executive
Board.
• SAP Global Security & Compliance partners with engineering, cloud
operations, and product organizations to drive secure development and
continuous improvement.
Vulnerability handling and coordinated disclosure
• SAP maintains a mature global vulnerability management program,
supported by regular security patching, continuous monitoring, and
responsible disclosure practices.
• We publish monthly SAP Security Patch Day updates and provide
transparency into vulnerability remediation activities.
• SAP’s Secure Software Development and Operations Lifecycle (Secure
SDOL) includes threat modelling, code scanning, secure coding
standards, and continuous testing.
• These processes help ensure SAP products meet high security standards
throughout their lifecycle.
Lifecycle management and security maintenance
• SAP delivers software updates, security notes, and lifecycle support
policies that help customers maintain secure SAP environments over
time
Through these efforts, SAP supports customers who must meet
CRA-aligned policies within their own environments — offering
secure-by-design solutions without overpromising CRA-specific
guarantees.
How SAP supports you – today and tomorrow
A trusted partner for secure digital transformation
SAP solutions are designed with industry established security principles that form a solid foundation as regulatory expectations evolve. While SAP is not
offering CRA-specific consulting or tailored compliance products, our long-standing commitment to security, transparency, and responsible lifecycle
management helps support your organization’s resilience objectives.
We’re with you — wherever compliance takes you next...
Our commitment to your
sustainable security and
resilience
SAP is unwavering in its commitment to partnering with customers and authorities
regarding our services and secure product development practices.
For more information, visit the SAP Trust CenterLinearrow:Straightwithsolidfill
© 2026 SAP SE or an SAP affiliate company. All rights reserved.
See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.
sustainable security and
resilience
SAP is unwavering in its commitment to partnering with customers and authorities
regarding our services and secure product development practices.
For more information, visit the SAP Trust CenterLinearrow:Straightwithsolidfill
© 2026 SAP SE or an SAP affiliate company. All rights reserved.
See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.