As of September 11, the European Union has ushered in a seismic shift in the digital landscape. The first wave of obligations under the EU’s Cyber Resilience Act (CRA) has officially taken effect, mandating that manufacturers report actively exploited vulnerabilities and severe security incidents. While the regulation is primarily aimed at those who design and build connected hardware, the ripple effects are being felt most acutely in the boardrooms of telecommunications operators.
To understand the implications of this shift, we sat down with Steven Offerein, VP of Product, Device Intelligence and Protection Services at CUJO AI. With over 15 years of experience spanning F-Secure, TalkTalk, and now a leadership role at one of the world’s foremost network security providers, Offerein provides a critical perspective on why the CRA is not merely a manufacturer’s burden, but an existential operational challenge for the modern telco.
The CRA: A Catalyst for Network-Wide Accountability
On the surface, the Cyber Resilience Act is a product-safety directive. It demands that connected devices—ranging from smart thermostats to high-end residential gateways—meet stringent security standards throughout their lifecycle. However, Offerein argues that the "manufacturer" definition is far broader than many operators realize.
"If you put your brand on a gateway or substantially modify a product in a way that affects its cybersecurity, you may find yourself in the manufacturer’s seat," Offerein explains. For many operators, the realization that they might be legally liable as a manufacturer for their Customer Premises Equipment (CPE) has sparked a frantic internal audit of their hardware supply chains.
Beyond the legal definition, there is the issue of scale. Operators manage millions of entry points into the home. When a zero-day exploit emerges, the traffic does not hit the manufacturer’s data center—it flows across the operator’s network. The CRA formalizes the reporting process, but it does nothing to remove the operator from the front lines of the battle.
Chronology of Compliance: Understanding the Timeline
A common misconception permeating the industry is that the CRA is a "December 2027 problem"—the date when full conformity requirements, including CE marking and comprehensive security standards, become mandatory for new products.
Offerein is quick to debunk this complacency. "The date that matters is September 11, 2026," he notes. "The reporting obligations apply to products already on the market, not just new ones. It is not a future concern; it is a present-day operational reality."
The Regulatory Roadmap:
- September 11, 2026: Initial reporting obligations take effect. Manufacturers (and operators qualifying as such) must report actively exploited vulnerabilities.
- The 24-Hour Window: Upon becoming aware of an actively exploited vulnerability or a severe security incident, organizations are on a strict 24-hour clock to provide an "early warning" to the relevant national Computer Security Incident Response Team (CSIRT) and ENISA.
- The 72-Hour Follow-up: A detailed notification, including technical context and mitigation plans, must follow within 72 hours.
- December 2027: Full implementation of the CRA, requiring comprehensive security assessments, Software Bills of Materials (SBOM), and defined support periods for all connected products.
The Visibility Gap: Why Operators Are in the Dark
"How can an operator managing 20 million gateways not know what’s connected to its own network?" This is the question that haunts network architects. The answer, according to Offerein, lies in the distinction between the gateway and the ecosystem behind it.
Operators maintain meticulous records of the hardware they ship. However, they lack a real-time, granular view of the hundreds of millions of disparate IoT devices—smart cameras, hubs, appliances, and legacy tech—connected to those gateways. These devices often use inconsistent identification protocols, making it impossible for a standard procurement database to track them.
"Real visibility means identifying devices by type, model, and firmware version continuously," Offerein explains. "Without this, when a vulnerability disclosure lands, the operator is forced into a state of paralysis. They cannot say, ‘We have 340,000 affected devices.’ They can only say, ‘We don’t know.’"

Implications: From Remediation to Mitigation
The CRA’s intent is to ensure vulnerabilities are patched. But what happens when a patch is impossible? This is the "uncomfortable reality" of the modern smart home.
"Walk into an average European home, and you’ll find devices whose manufacturers have gone bankrupt, cheap IoT products that lack update mechanisms, and functional equipment that has simply aged out of support," says Offerein. "For these devices, ‘install the patch’ is not an option."
This creates a new mandate for operators. If the device cannot be patched, the protection must come from the network layer. By utilizing the gateway as a security perimeter, operators can block malicious traffic, detect anomalies, and contain compromised devices before they become part of a larger botnet. This shifts the role of the operator from a mere "pipe provider" to a guardian of the digital home.
The RFP Revolution: Changing How Telcos Buy
Historically, Request for Proposals (RFPs) in the telecommunications sector were driven by two factors: price and performance. Cybersecurity was often treated as an afterthought or a "nice-to-have" feature. The CRA is forcing a fundamental change in these procurement cycles.
Offerein suggests that operators must now prioritize three key areas:
- Support Commitments: Defining exactly how long a manufacturer will provide security updates and what that "support" entails.
- Software Bills of Materials (SBOM): Demanding transparency regarding the code within their devices.
- Vulnerability Disclosure Processes: Ensuring a legally binding, clear line of communication between the vendor and the operator to meet the 24-hour reporting mandate.
"Operators have historically been comfortable letting CPE sit in the field for a long time to save on replacement costs," Offerein observes. "The CRA makes this risky. If a device has an end-of-support date, the operator must now plan for it—either by extending support contractually, replacing the hardware, or assuming the liability of a vulnerable product."
Conclusion: The Path Forward
The Cyber Resilience Act is not a hurdle to be jumped; it is a framework for a more secure, sustainable future. While compliance may seem like a "paperwork exercise" to some, it is actually a catalyst for much-needed modernization.
For operators, the path forward is clear. First, conduct an audit to determine where they stand as "manufacturers" under the law. Second, invest in the operational processes required to meet the 24-hour reporting window. Third, and perhaps most importantly, invest in device intelligence.
"Visibility is the baseline," Offerein concludes. "Operators that can accurately identify their device population and apply network-level protections will not only be compliant with the CRA—they will be providing a level of service and security that distinguishes them in a crowded, and increasingly dangerous, market."
As the industry grapples with these new rules, the message from experts like Offerein is consistent: the age of "set and forget" for connected hardware is over. In its place is an era of continuous vigilance, where the operator’s ability to see, understand, and protect the home network becomes their most valuable asset.
