The European Union is currently redrawing the map of digital accountability. With the phased implementation of the Cyber Resilience Act (CRA), the legal landscape for connected products is undergoing its most significant transformation in decades. While the regulation is frequently categorized as a "manufacturer’s law," its shockwaves are set to hit network operators—Internet Service Providers (ISPs) and telecommunications giants—with unexpected force.
As the first major reporting obligations approach, the industry is grappling with a fundamental question: Where does the manufacturer’s responsibility end, and the operator’s begin? To explore these shifting boundaries, we sat down with Steven Offerein, VP of Product, Device Intelligence and Protection Services at CUJO AI, to discuss the operational realities of the CRA and why waiting until 2027 to prepare could be a catastrophic mistake.
Main Facts: Redefining the "Manufacturer"
The Cyber Resilience Act (CRA) is the EU’s first comprehensive piece of legislation aimed at the cybersecurity of "products with digital elements." At its core, it seeks to ensure that any product connected to a network is secure throughout its entire lifecycle.
However, a common misconception among telecom executives is that the CRA only applies to those who physically assemble hardware. As Offerein points out, the legal definition of a "manufacturer" under the CRA is much broader.
"Operators are not always just customers under the CRA; they can also be subject to it," Offerein explains. "If you put your brand on a gateway or substantially modify a product in a way that affects its cybersecurity, you may find yourself in the manufacturer’s seat, with all the associated legal obligations."
For many operators, their Customer Premises Equipment (CPE) portfolio—the routers and gateways provided to millions of homes—falls into this category. By white-labeling hardware or customizing firmware, operators effectively become the "manufacturer of record." This means they are legally responsible for vulnerability handling, software updates, and, crucially, mandatory incident reporting.
Chronology: The Road to Compliance
While the full weight of the CRA—including CE marking and essential security requirements—does not become mandatory until December 2027, the timeline for reporting is much more aggressive.
Phase 1: September 11, 2024 – Initial Awareness
The industry began the transition toward the new rules, with the final text of the CRA being solidified and the countdown beginning for the first major deadline.
Phase 2: September 11, 2026 – Mandatory Reporting Begins
This is the "hidden" deadline that many in the industry are overlooking. From this date, manufacturers (including operators who brand their own CPE) must report any actively exploited vulnerabilities or severe security incidents.
"The reporting obligations apply to products already on the market, not just new ones," Offerein warns. "This isn’t a future problem; it’s a legacy problem that becomes a legal requirement in 2026."
Phase 3: December 2027 – Full Conformity
The final stage requires all products to meet strict "security by design" standards. This includes defined support periods, mandatory security updates, and a formal conformity assessment before a product can carry the CE mark in the EU.
Supporting Data: The Scale of the "Blind Spot"
The challenge for operators is one of sheer scale. While an operator may have a firm grasp on the 20 million gateways they have shipped to customers, they are often blind to the ecosystem of devices operating behind those gateways.
The Connectivity Gap
Data from CUJO AI suggests that for every gateway in a modern home, there are typically 10 to 20 connected devices. Behind a fleet of 20 million gateways, an operator is looking at a population of 200 million to 400 million connected devices—ranging from smart TVs and laptops to cheap IoT lightbulbs and legacy security cameras.
"Real visibility means identifying those devices by type, model, and software version, continuously and at population scale," says Offerein. "When a vulnerability disclosure lands, the difference is being able to say, ‘We have 340,000 potentially affected devices,’ rather than, ‘We genuinely don’t know.’"
The "Abandoned" Device Reality
A significant portion of the devices currently connected to European networks are "orphaned"—meaning the manufacturer no longer provides updates, or the company may no longer exist. These devices represent a permanent security risk that cannot be patched.
Under the CRA, new products must have a defined support period, but the act cannot retroactively force a defunct manufacturer to update a 10-year-old smart camera. This leaves the operator’s network as the only line of defense.
Official Responses: Insights from CUJO AI
In our interview, Steven Offerein highlighted three critical areas where operators must pivot their strategy to survive the CRA era.

1. The 24-Hour Reporting Pressure
The CRA mandates an "early warning" within 24 hours of becoming aware of an actively exploited vulnerability. This is followed by a fuller notification within 72 hours.
"A 24-hour reporting window puts pressure on the entire vulnerability-response process," Offerein notes. "It’s not just a paperwork exercise. You need the processes in place to establish what happened and respond instantly. If you are debating who owns the problem when the clock starts, you’ve already lost."
2. Detection Without Identification is Useless
Offerein argues that simply knowing an exploit is circulating on the network is insufficient. Operators must be able to map a Common Vulnerabilities and Exposures (CVE) ID to specific households.
"Identification turns a CVE from an abstract industry problem into a sized, addressable operational task," he says. "I think the ability to map a disclosure to an affected device population quickly will increasingly become a baseline operator capability, much like outage mapping is today."
3. The Limits of Device Intelligence
While many vendors claim to offer "CRA compliance in a box," Offerein is refreshingly honest about the limits of technology.
"Let me be clear: no platform makes you CRA compliant. Compliance involves processes, documentation, and legal accountability. Where device intelligence helps is at the operational layer—giving you the visibility needed to respond at the scale of a broadband network."
Implications: A Shift in the Telecom Business Model
The CRA is set to change not just how operators secure their networks, but how they buy and manage hardware.
The End of "Price First" RFPs
Historically, Request for Proposals (RFPs) for gateways were driven by price and hardware performance (Wi-Fi speeds). The CRA shifts the focus to the total cost of ownership over the product’s lifecycle.
"Support periods, vulnerability handling, and update capability used to be secondary criteria," says Offerein. "The CRA gives those considerations much more weight. It forces more honesty around lifecycle management."
Sustainability and the Circular Economy
There is a growing concern that the CRA might force operators to pull functional hardware from the field simply because software support has ended. However, Offerein sees a potential for a more sustainable outcome.
"The wasteful pattern today isn’t hardware living too long; it’s hardware being abandoned by software long before the silicon is done," he observes. By requiring longer, contractually defined support periods, the CRA could actually extend the useful life of hardware, reducing the environmental impact of replacing millions of units every few years.
The Network as a Shield
Perhaps the most significant implication is the formalization of the operator’s role as a security provider. If a device in a customer’s home is vulnerable and cannot be patched, the operator’s gateway becomes the "mitigation layer."
Network-level security can block malicious traffic, detect botnet activity, and isolate compromised devices without requiring any action from the end-user. As the CRA moves responsibility toward the product, the network remains the essential safety net for everything the law cannot reach.
Conclusion: The Operator’s Action Plan
As the September 2026 deadline for reporting approaches, Offerein suggests that operators take three immediate steps:
- Settle the Role Question: Conduct a legal audit of the CPE portfolio to determine if the operator is a "manufacturer," "importer," or "distributor" under the CRA.
- Rehearse the Reporting Path: Establish internal escalation and on-call processes so that a 24-hour reporting window can be met without panic.
- Invest in Visibility: Move beyond procurement databases and implement real-time device intelligence to understand what is actually connected to the network.
The Cyber Resilience Act is a clear signal from the EU: the era of "connecting it and forgetting it" is over. For operators, the challenge is no longer just providing a pipe for data, but ensuring the integrity of the millions of devices that call that pipe home.
About Steven Offerein
Steven Offerein is the VP of Product, Device Intelligence and Protection Services at CUJO AI. With over 15 years of experience in cybersecurity and telecommunications, including senior roles at F-Secure and TalkTalk, he is a leading voice on the intersection of regulatory compliance and network security.
