Secure-by-Design: The EU Cyber Resilience Act

A new baseline for secure-by-design technologiesThe Cyber Resilience Act (CRA) is a major new EU regulation designed to improve the cybersecurity of products with digital elements. It aims toensure that specific hardware and software placed on the EU market meet consistent cybersecurity requirements across their lifecycle.CRA Download the Document

EU Cyber ResilienceSAP's Commitment toAct (CRA)Supporting your continued compliance – wherever regulationstake you nextCRA Compliance | SAP Solutions© 2026 SAP SE or an SAP affiliate company. All rights reserved.See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.
Table ofcontents3 CRA strengthens the security ofdigital products in the EU4 How SAP is supporting your ongoingCRA compliance4 How SAP supports you — today andtomorrow5 Our commitment to cybersecurityand partnership
CRA strengthens the security of digital products in the EUA new baseline for secure-by-design technologiesThe Cyber Resilience Act (CRA) is a major new EU regulation designed to improve the cybersecurity of products with digital elements. It aims toensure that specific hardware and software placed on the EU market meet consistent cybersecurity requirements across their lifecycle.CRA represents a shift toward strong cybersecuritybuilt into digital products from the outset — helpingreduce risks and strengthening resilience across theEuropean digital ecosystem.Line arrow: Straight with solid fillWith obligations for manufacturers, importers, and distributors, CRAintroduces requirements for: Secure product design, development, and production. Vulnerability handling processes Transparency on cybersecurity features and proper use Reporting of actively exploited vulnerabilities and incidents Ongoing security support throughout product lifecycleThe CRA affects a wide range of digital products marketed or deliveredwithin the EU. As organizations modernize their techno logy landscapes,the regulation reinforces:What CRA means for SAP customers?Helping you understand the new expectations The need for transparent security information Stronger vulnerability and patch management Consistent secure-by-design practices Clarity over supplier responsibilitiesFor SAP customers, CRA requires alignment with expectationsaround transparency, secure dev elopment, and multi-layeredprotection, as SAP has demonstrated with its existing offerings.Thus, SAP’s compliance journey encompasses a harmonizedframework that complements the security posture customersalready expect from SAP’s solutions.3| 6
4| 6How SAP is supporting your ongoing CRA complianceSAP has long embedded security into its engineering standards,operations, and governance. Our approach aligns with many of the coreprinciples reflected in the CRA.Secure development and responsible product stewardshipStrong executive governance of cybersecurityEstablished secure development processesLine arrow: Straight with solid fill SAP’s cybersecurity strategy is shaped and supported by our ExecutiveBoard. SAP Global Security & Compliance partners with engineering, cloudoperations, and product organizations to drive secure development andcontinuous improvement.Vulnerability handling and coordinated disclosure SAP maintains a mature global vulnerability management program,supported by regular security patching, continuous monitoring, andresponsible disclosure practices. We publish monthly SAP Security Patch Day updates and providetransparency into vulnerability remediation activities. SAP’s Secure Software Development and Operations Lifecycle (SecureSDOL) includes threat modelling, code scanning, secure codingstandards, and continuous testing. These processes help ensure SAP products meet high security standardsthroughout their lifecycle.Lifecycle management and security maintenance SAP delivers software updates, security notes, and lifecycle supportpolicies that help customers maintain secure SAP environments overtimeThrough these efforts, SAP supports customers who must meetCRA-aligned policies within their own environments — offeringsecure-by-design solutions without overpromising CRA-specificguarantees.How SAP supports you – today and tomorrowA trusted partner for secure digital transformationSAP solutions are designed with industry established security principles that form a solid foundation as regulatory expectations evolve. While SAP is notoffering CRA-specific consulting or tailored compliance products, our long-standing commitment to security, transparency, and responsible lifecyclemanagement helps support your organization’s resilience objectives.We’re with you — wherever compliance takes you next...
Our commitment to yoursustainable security andresilienceSAP is unwavering in its commitment to partnering with customers and authoritiesregarding our services and secure product development practices.For more information, visit the SAP Trust CenterLinearrow:Straightwithsolidfill© 2026 SAP SE or an SAP affiliate company. All rights reserved.See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.