Cyprus firms face new EU cyber rules as CRA obligations begin
Cypriot manufacturers and software developers must now report exploited vulnerabilities and severe security incidents under the EU's Cyber Resilience Act, with smaller firms facing the toughest compliance challenge.
Cypriot manufacturers and software developers are entering the most demanding phase of Europe's new cybersecurity regime, Research Deputy Minister Nicodemos Damianou said this week, as reported by Cyprus Mail, with new obligations taking effect and smaller firms facing the practical challenge of meeting them.
Speaking at the 'Building CRA Compliance through Horizontal Cybersecurity Standards' conference in Nicosia, Damianou used an unlikely example to explain why Europe's Cyber Resilience Act reaches well beyond the traditional technology sector: a fish tank. A few years ago, attackers gained access to a casino's network through a smart thermometer installed in its lobby aquarium, then moved through the system to its high-roller database.
"Nobody who bought that thermometer thought they were making a decision that affected cybersecurity," Damianou said, adding that this was "precisely the point" of the CRA. For the first time, security becomes a property of the product itself, designed in from the outset, maintained throughout its support period, and made the manufacturer's responsibility rather than the customer's.
Since September 11, manufacturers have been required to report actively exploited vulnerabilities and severe security incidents affecting products with digital elements through the EU's reporting arrangements under cybersecurity agency ENISA. The full set of essential requirements will apply from December 11, 2027.
Damianou also pointed to newer risks posed by autonomous AI agents, citing recent incidents involving OpenAI and Hugging Face, as well as Anthropic. For Cyprus, he said, such risks carry particular weight because of the island's reliance on connected infrastructure and international supply chains. "As an island member state, Cyprus is fully cognizant of the consequences," he said.
European standardisation bodies CEN, CENELEC and ETSI are developing harmonised standards intended to help companies meet the CRA's requirements, covering secure product design, risk management, vulnerability handling, access management and encryption. Damianou said his main concern was smaller businesses: "Most Cypriot manufacturers and software developers do not have a compliance department," he said, arguing that for such firms "a practical, accessible standard is the difference between compliance as a burden and compliance as a competitive advantage".
What it means for residents
The CRA will quietly reshape the electronics and software Cypriots buy and the firms that make them. If you run a small tech company or import connected devices, the reporting duties are already live, and the full requirements arrive in 2027.
- Businesses: Companies making or selling products with digital elements in the EU must now report exploited vulnerabilities and severe incidents via ENISA. Budget for this early, especially if you have no compliance staff.
- Consumers: Expect more secure devices and longer support periods, but also possible price adjustments as manufacturers absorb compliance costs.
- Practical step: If you run an SME in manufacturing or software, check which of your products fall under the CRA and start mapping the harmonised standards now rather than waiting for 2027.
This text is written from the source article and is not a translation of it.