Cyber Resilience Act: Impact on Patent Software
The CRA sets new requirements for patent software vendors and users. What the regulation means and how to prepare.
The Cyber Resilience Act Applies to Your Patent Software: What You Need to Know Now
The Cyber Resilience Act (CRA), adopted in October 2024 and in force since December 2024, introduces the most comprehensive cybersecurity regulation for software products the EU has ever enacted. From September 11, 2027, all products with digital elements - including patent software - must meet CRA requirements and bear the CE marking.
For patent firms and IP departments that rely on specialized software for search, drafting, filing, and portfolio management, the CRA has two dimensions: as users of this software, they must understand what the CRA demands from their vendors; and as those responsible for their IT infrastructure, they must ensure their software landscape is CRA-compliant.
What the CRA Requires From Software Products
The CRA defines cybersecurity requirements for "products with digital elements" - a deliberately broad category encompassing both hardware with software components and pure software products. Patent software, whether cloud-based or on-premise, clearly falls within scope.
The core requirements (Annex I of the CRA) include:
Security by design: Software must be designed to ensure an appropriate level of cybersecurity. This means secure default configurations, encryption of sensitive data, authentication mechanisms, and protection against unauthorized access.
Vulnerability handling: Manufacturers must actively identify and remediate vulnerabilities in their products. This encompasses a documented vulnerability handling process, remediation of known vulnerabilities without undue delay, and informing users about security updates.
Software Bill of Materials (SBOM): Manufacturers must provide a machine-readable inventory of all software components. This enables users to identify vulnerabilities in third-party components and assess supply chain attack risks.
Security updates: Manufacturers must provide free security updates for the entire support period (at least five years or the expected product lifetime, whichever is shorter).
Obligations for Patent Software Vendors
For patent software vendors - whether established players like Clarivate, Questel, and Anaqua or specialized startups - the CRA introduces significant new obligations.
Conformity assessment: Before placing a product on the market, the manufacturer must conduct a conformity assessment. For standard software, a self-assessment under Annex VIII typically suffices. For software integrated into critical infrastructure (such as at patent offices), assessment by a notified body may be required.
CE marking: Following successful conformity assessment, the product must bear the CE marking. This is not decorative - it is the legally binding declaration that the product meets CRA requirements.
Reporting obligations: Actively exploited vulnerabilities must be reported within 24 hours to the competent CSIRT (Computer Security Incident Response Team) and to ENISA. A detailed report must follow within 72 hours.
Technical documentation: Comprehensive technical documentation must be created and maintained demonstrating conformity with all CRA requirements. This documentation must be accessible to market surveillance authorities on request.
Impact on Users: What Firms Must Consider
While the CRA primarily defines obligations for manufacturers, users of patent software have concrete responsibilities.
Apply security updates promptly: The CRA obligates manufacturers to provide updates - but users must actually install them. A firm that ignores known security updates acts not only negligently under the CRA framework but also risks GDPR violations if the unpatched software leads to a data breach.
Prefer products with CE marking: From September 2027, firms should ensure during software procurement that products are CRA-compliant. Software without CE marking may not be regularly placed on the EU market after this date.
Evaluate SBOMs: The Software Bill of Materials provided by the manufacturer should be regularly checked against known vulnerability databases (CVE) - ideally through automated scanning tools that flag newly discovered vulnerabilities in deployed components.
Update vendor due diligence: Requirements for vetting software vendors must be expanded to include CRA-specific points: Does a CE certificate exist? How is the vulnerability handling process organized? What is the committed support period? What are the vendor's incident response capabilities?
CRA in Conjunction With NIS2 and AI Act
The CRA does not exist in isolation but as part of a regulatory ecosystem that also includes the NIS2 Directive and the AI Act. For patent software users, this creates overlapping requirements.
NIS2: Patent firms serving as providers to essential or important entities may indirectly fall within the scope of the NIS2 Directive. NIS2 requires, among other things, cybersecurity risk management, incident response plans, and reporting obligations for significant security incidents.
AI Act: Patent software containing AI components is additionally subject to AI Act requirements. The interaction between CRA and AI Act is governed by Article 8 CRA: for AI systems falling under the AI Act, the CRA cybersecurity requirements are deemed met if the AI Act requirements are fulfilled - provided the AI Act requirements substantively cover the CRA requirements.
In practice, this means a patent firm using AI-powered patent software in the cloud must ensure the vendor is CRA-compliant, meets AI Act requirements, complies with GDPR requirements as a data processor, and implements NIS2-relevant security measures where applicable. Four regulatory regimes, one software product.
Compliance Timeline: What Applies When
The CRA provides a staggered transition period.
Since June 11, 2026, reporting obligations for actively exploited vulnerabilities and severe security incidents apply. Manufacturers must have their reporting processes established.
From September 11, 2027, all CRA requirements apply in full. Products with digital elements may only be placed on the EU market with CE marking.
For firms as users, this means: by September 2027, verify whether all deployed software products are or will be CRA-compliant. Contact software vendors and inquire about their CRA roadmap. Adapt procurement processes to anchor CRA conformity as a selection criterion.
Practical Preparation Steps
The concrete preparation steps for patent firms are manageable, but they must begin now.
First, create a software inventory. Which software products with digital elements are deployed? Which version? Which vendor? What support period?
Second, conduct vendor assessments. Do the vendors of deployed software have a CRA compliance strategy? When is CE marking expected? How is the vulnerability handling process organized? Request written confirmation of compliance timelines.
Third, formalize update processes. Ensure security updates are applied within defined timeframes - not "when there is time" but according to a documented process with clear responsibilities and escalation procedures.
Fourth, establish SBOM management. Build the capability to receive, store, and check SBOMs against CVE databases - either manually or ideally through automated tools. This capability will become standard practice; building it early avoids scrambling when the September 2027 deadline arrives.
Conclusion
The Cyber Resilience Act closes the last major gap in the EU's cybersecurity regulatory framework. For patent firms, it primarily transforms the vendor relationship: more transparency, more security, more obligations on both sides. Those who prepare now will experience September 2027 as an organizational formality. Those who wait risk deploying non-compliant software - with all the regulatory and liability consequences that entails.