The CRA finding can generally be integrated into the deal.
Record product roles, responsibilities and evidence. The SPA should reflect the findings in warranties and information covenants.
Cyber Resilience Act in acquisitions: review product roles, vulnerability handling, conformity documents and SPA protection.
BRANDAUER Rechtsanwälte
Salzburg law firm for corporate, company and transaction law
Every transaction is handled by a coordinated team of lawyers, legal staff and specialists. In company acquisition matters we look at structure, contract, tax and liability together.
In an acquisition, the Cyber Resilience Act is not just another IT security chapter. It can directly affect product-related obligations of a target that manufactures, imports or distributes software, hardware or connected products.
Before closing, the buyer should understand the target’s role in the supply chain, whether vulnerability handling works and whether conformity and security documentation is reliable. Otherwise a product compliance issue becomes a liability and cost risk after closing.
The questions separate general cybersecurity from concrete CRA product duties.
Already know you want to get in touch? Go straight to the enquiry form.
Then product compliance must be reviewed in addition to IT operations.
Record product roles, responsibilities and evidence. The SPA should reflect the findings in warranties and information covenants.
If roles, supply chain or vulnerability processes are open, the buyer should consider a remediation plan, holdback, indemnity or condition.
The CRA complements NIS2 cybersecurity due diligence, but does not replace it. NIS2 looks more at organisational and operator obligations. The CRA focuses on products with digital elements.
The data room should therefore show whether the target is a manufacturer, importer, distributor or service provider. That role determines which documents, processes and risks the buyer takes over.
In a software or SaaS business, source code, open-source components, third-party modules, update processes and security reports are closely linked to CRA risk.
The review should show whether vulnerabilities are documented, assessed and remediated. Unclear responsibility between manufacturer, integrator and reseller belongs in the risk list.
CRA issues may overlap with product liability and recall risks. Warranties should therefore not refer only to abstract compliance, but cover portfolio, documentation, known vulnerabilities and supply chain.
If evidence is missing, the buyer may need a holdback, indemnity, condition or binding remediation plan.
The overview shows which finding can trigger which agreement consequence.
| Point | Review | Consequence |
|---|---|---|
| Product role Manufacturer, importer, distributor or service provider? | Role-based warranty | |
| Documentation Conformity and security documents available? | Disclosure and delivery duty | |
| Vulnerabilities Vulnerability handling reliable? | Covenant and indemnity | |
| Supply chain Third-party components and open source reviewed? | IT and IP warranties |
The concrete drafting depends on the target, data room and negotiating position.
Practical point: A generic IT security sentence is not enough. If the target offers products with digital elements, the deal should capture the concrete product role and existing evidence.
No. NIS2 mainly concerns organisational cybersecurity of certain entities, while the CRA focuses on digital products.
Because components, open source and suppliers can determine which vulnerabilities and evidence the buyer takes over.
Yes, if material product duties, documents or known vulnerabilities remain unresolved before closing.
When buying a company, structure, review and contract decide. Call us directly or send an email, callback within one business day.
Address
BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg
Phone
+43 662 6280000