Blog WatchGuard

The Cyber Resilience Act: What MSPs Need to Know About the New European Guidance

The new guidance on the Cyber Resilience Act clarifies how to apply its requirements. Find out what it means for tech vendors and what MSPs need to keep on their radar.

The European Commission has published its first official guidance to help businesses implement the Cyber Resilience Act (CRA)—the EU regulation establishing cybersecurity requirements for products with digital elements.

The timeline is critical: reporting obligations for actively exploited vulnerabilities and severe incidents take effect on September 11, 2026, while the core CRA requirements will become mandatory from December 11, 2027.

For MSPs, the CRA isn't just a matter of regulatory compliance. It directly impacts the technology and cybersecurity solutions you rely on to protect your clients.

The new guidance helps clarify the regulation's practical details—such as which products are covered, how to conduct risk assessments, what counts as a substantial modification, how long support must last, and what to do when a vulnerability is discovered or an incident occurs.

Underlying all these requirements is one core principle: security must be built into products across their entire lifecycle—from design to end-of-support.

Security Starts Before Launch

The CRA requires tech vendors to build cybersecurity into products right from design and development. This means identifying and assessing risks, implementing appropriate security controls, and verifying that those safeguards work before a product is launched.

When it comes to cybersecurity, the takeaway is clear: product security doesn't stop once a new version goes live.

Software evolves, new threats emerge, and newly discovered vulnerabilities come to light. Because of this, risk assessments and security controls must evolve alongside the product.

In practice, this means integrating security into development processes, running tests and validations, documenting the results, and maintaining mechanisms to identify and remediate issues throughout the entire lifecycle.

It's an approach that WatchGuard calls Secure by Design—building security directly into the development process, not treating it as a final checklist item.

Vulnerability Management Requires a Process, Not a Reaction

One of the key areas where the CRA introduces more concrete requirements is vulnerability management.

When a potential vulnerability is identified, tech vendors must answer several key questions quickly:

  • What is the root cause of the issue?
  • Which products and versions are affected?
  • What level of risk does it pose to users?
  • Is the vulnerability being actively exploited?
  • What fix or patch is needed?
  • How will the update be distributed?
  • What information do partners and clients need?

Answering these questions quickly requires defined processes and clear accountability.

At WatchGuard, our Product Security Incident Response Team (PSIRT) centralizes the management of security advisories related to our products. The team coordinates investigations with the relevant teams, determines the scope of identified vulnerabilities, and oversees necessary remediation actions.

When appropriate, WatchGuard issues security notices to outline affected products and versions, recommended client actions, and available fixes or updates.

This cycle of identification, investigation, remediation, and disclosure is vital as new European regulations raise the bar for vulnerability management.

Support Is Also Part of Security

The CRA also puts a strong focus on the duration of product security support. As a general rule, the regulation mandates a minimum support period of five years, unless the expected product lifespan is shorter.

For tech vendors and clients alike, this makes the product lifecycle even more important.

A product shouldn't be considered secure simply because it has no known vulnerabilities at launch. Security must be maintained throughout the entire period clients rely on it.

To achieve this, processes must be in place to:

  • Identify new vulnerabilities
  • Assess their impact
  • Develop and test fixes
  • Securely distribute updates
  • Communicate risks and required actions
  • Maintain clear information on product support timeframes and end-of-life (EOL) schedules

For MSPs, this information is equally important when planning their clients' IT lifecycles and ensuring they don't continue running unsupported solutions.

From Compliance to Security You Can Prove

At WatchGuard, many of these processes are already built into how we develop and maintain our products.

Our approach combines Secure by Design principles, security testing throughout development, vulnerability management, coordinated incident response, security updates, and active communication with partners and clients.

This makes it possible to address the CRA through concrete, verifiable processes—rather than treating compliance as a requirement separate from product development and maintenance.

For MSPs, this distinction matters.

When a client asks how a cybersecurity solution supports their compliance goals, the answer shouldn't stop at a certification or a declaration of conformity. MSPs should also be able to explain how the product is developed, how vulnerabilities are identified and managed, how fixes are delivered, and how long security support lasts.

These are the elements that help turn compliance into something tangible.

The CRA Is Just the Beginning

The Cyber Resilience Act is part of an increasingly demanding European regulatory landscape. Regulations and standards such as NIS2, DORA, and other EU cybersecurity initiatives are raising expectations for how organizations manage technology risk and how vendors develop and maintain their products.

For tech vendors, this means product security—and the ability to prove it—will become increasingly critical.

For MSPs, it means their clients’ questions will continue to evolve.

That is why, beyond complying with any single regulation, the goal should be to partner with vendors who can demonstrate that security is built into the entire lifecycle of their products—and who have clear processes in place to respond when new risks emerge.

At WatchGuard, we continue to evolve our processes and solutions to help our partners and their clients navigate this shifting regulatory and threat landscape.

Resources for MSPs

For MSPs, understanding how a tech vendor manages product security is just as important as keeping up with new regulations. The following WatchGuard resources can help you dive deeper into the processes and practices behind our product security:

  • WatchGuard Trust Center—Centralizes information on our security practices, reliability, and compliance, as well as the status of our products and services. It also provides access to information issued by the Product Security Incident Response Team (PSIRT).
  • Security Advisories—Review WatchGuard security advisories, including identified vulnerabilities, affected products, severity levels, CVE IDs, status, and publication dates.
  • Network Security—Information on WatchGuard’s network security solutions and the capabilities available to protect client environments.

These resources deliver practical insights MSPs can use to evaluate solutions, plan updates, and show their clients how tech vendor security processes support their compliance goals.