Deal
Due diligence

Cyber Resilience Act in an acquisition: product obligations before closing

Cyber Resilience Act in acquisitions: review product roles, vulnerability handling, conformity documents and SPA protection.

BRANDAUER Rechtsanwälte
Your law firm

BRANDAUER Rechtsanwälte

Salzburg law firm for corporate, company and transaction law

Every transaction is handled by a coordinated team of lawyers, legal staff and specialists. In company acquisition matters we look at structure, contract, tax and liability together.

14 August 2026 · Mag. Bernhard Brandauer, Rechtsanwalt

In an acquisition, the Cyber Resilience Act is not just another IT security chapter. It can directly affect product-related obligations of a target that manufactures, imports or distributes software, hardware or connected products.

Before closing, the buyer should understand the target’s role in the supply chain, whether vulnerability handling works and whether conformity and security documentation is reliable. Otherwise a product compliance issue becomes a liability and cost risk after closing.

Start CRA review

Are product obligations under control before closing?

The questions separate general cybersecurity from concrete CRA product duties.

Already know you want to get in touch? Go straight to the enquiry form.

01 Question 1

Does the target manufacture, import or distribute digital products or components?

Then product compliance must be reviewed in addition to IT operations.

All paths at a glance

Overview of all answers.

01

The CRA finding can generally be integrated into the deal.

Record product roles, responsibilities and evidence. The SPA should reflect the findings in warranties and information covenants.

02

The CRA finding needs a concrete solution before closing.

If roles, supply chain or vulnerability processes are open, the buyer should consider a remediation plan, holdback, indemnity or condition.

Review product role, not only IT security

The CRA complements NIS2 cybersecurity due diligence, but does not replace it. NIS2 looks more at organisational and operator obligations. The CRA focuses on products with digital elements.

The data room should therefore show whether the target is a manufacturer, importer, distributor or service provider. That role determines which documents, processes and risks the buyer takes over.

Review supply chain, open source and vulnerabilities

In a software or SaaS business, source code, open-source components, third-party modules, update processes and security reports are closely linked to CRA risk.

The review should show whether vulnerabilities are documented, assessed and remediated. Unclear responsibility between manufacturer, integrator and reseller belongs in the risk list.

Draft SPA protection for product duties

CRA issues may overlap with product liability and recall risks. Warranties should therefore not refer only to abstract compliance, but cover portfolio, documentation, known vulnerabilities and supply chain.

If evidence is missing, the buyer may need a holdback, indemnity, condition or binding remediation plan.

Deal grid

CRA review points in an acquisition

The overview shows which finding can trigger which agreement consequence.

CRA review points in an acquisition
Point Review Consequence
Product role Manufacturer, importer, distributor or service provider? Role-based warranty
Documentation Conformity and security documents available? Disclosure and delivery duty
Vulnerabilities Vulnerability handling reliable? Covenant and indemnity
Supply chain Third-party components and open source reviewed? IT and IP warranties

The concrete drafting depends on the target, data room and negotiating position.

Practical point: A generic IT security sentence is not enough. If the target offers products with digital elements, the deal should capture the concrete product role and existing evidence.

Frequent questions

Frequent questions on the Cyber Resilience Act in deals.

Is the CRA the same as NIS2? +

No. NIS2 mainly concerns organisational cybersecurity of certain entities, while the CRA focuses on digital products.

Why does the supply chain matter? +

Because components, open source and suppliers can determine which vulnerabilities and evidence the buyer takes over.

Can CRA justify a closing condition? +

Yes, if material product duties, documents or known vulnerabilities remain unresolved before closing.

Topics
Cyber Resilience ActProduct obligationsDue diligenceSoftwareAcquisition

Structuring a deal, reviewing a contract, securing the risks?

When buying a company, structure, review and contract decide. Call us directly or send an email, callback within one business day.

Contact

A direct line to the firm.

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg