Cybersecurity is becoming part of product responsibility.
By: Hans Risseeuw
European cybersecurity legislation is changing the way technology companies develop, maintain, and market products. Therefore, the FHI Cyber Security member meeting on September 2 in Leusden focused not only on new obligations but, above all, on the practical implications for organizations and their supply chain partners.
With the NIS2 Directive and the Cyber Resilience Act, cybersecurity is shifting from a technical focus to a demonstrable business responsibility. Security impacts the entire product lifecycle: from design and production to updates, maintenance, and incident handling. Responsibilities within the supply chain are also becoming more explicit. As a result, suppliers, manufacturers, and distributors must more clearly define who is responsible for what.
From regulation to product development
Wim Boonstra of Bureau Veritas placed NIS2 and the Cyber Resilience Act within the broader development of European legislation. Jarek Bieńkowski of the National Inspectorate for Digital Infrastructure subsequently addressed the shift required by the CRA. The first reporting obligation under this regulation applies from September 11, 2026. Companies must therefore prepare not only for technical product requirements, but also for processes that enable them to identify, assess, and report vulnerabilities and incidents in a timely manner.
This calls for collaboration between product development, IT, quality management, legal affairs, and the executive board. Those who leave cybersecurity solely to the IT department miss a significant part of the issue. The new rules directly impact design choices, documentation, supplier agreements, and support throughout the product lifecycle.
Continuity requires access to keys
A concrete supply chain risk is the management of cryptographic keys. Sander Remans of Escrow Alliance demonstrated why access to these keys is essential for secure boot, firmware updates, authentication, and secure communication, among other things. When a supplier fails, maintenance, updates, and even production can come to a standstill without proper safeguards. Key escrow can then contribute to both continuity and demonstrable compliance with the CRA.
Adithya Madanahalli from Würth Elektronik approached the CRA from the perspective of embedded systems and connected devices. Implementation is particularly complex for products with a long lifecycle. Hardware limitations, firmware, connectivity, and long-term support must be taken into account early in the development process. In this context, the CRA can be more than just a compliance issue: security by design can lead to better products, clearer responsibilities, and greater customer trust.
Preparing for the moment things go wrong
Mart Marconi explained the role of the National Cyber Security Centre and addressed the current Dutch cybersecurity landscape. The focus was on support during incidents, reporting them, and the NCSC's contribution to digital resilience.
Richard van Eck and Jurgen Struiksma of Hiscox and Klap Verzekeringsmakelaar subsequently translated cyber risk into business practice. A cyber incident can lead to operational downtime, financial damage, and liability issues. Preparation therefore also means knowing what needs to be done in the first 72 hours, how incident response is organized, and which risks are insurable.
The common thread of the afternoon was clear: cybersecurity is not a standalone IT project. It is becoming a structural part of product quality, risk management, and business continuity. Those who define responsibilities now and anchor security in product and supply chain processes will prevent new regulations from being treated merely as a deadline in the future.
FHI supports the members. Do you have questions about CRA and NIS2, or would you like to receive the presentations? Please contact Marc Berkouwer.