[{"data":1,"prerenderedAt":469},["ShallowReactive",2],{"navigation-docs_en":3,"/en/blog/cyber-resilience-act-september-2026-microsoft-smes-public-sector-posts_en":51,"/en/blog/cyber-resilience-act-september-2026-microsoft-smes-public-sector-surround-posts_en":459},[4],{"title":5,"path":6,"stem":7,"children":8,"page":25},"En","/en","en",[9],{"title":10,"path":11,"stem":12,"children":13,"page":25},"Docs","/en/docs","en/1.docs",[14,26],{"title":15,"path":16,"stem":17,"children":18,"icon":25},"Getting Started","/en/docs/getting-started","en/1.docs/1.getting-started/1.index",[19,21],{"title":20,"path":16,"stem":17,"children":-1},"Introduction",{"title":22,"path":23,"stem":24,"children":-1},"Migration Roadmap","/en/docs/getting-started/migration-fahrplan","en/1.docs/1.getting-started/2.migration-fahrplan",false,{"title":27,"path":28,"stem":29,"children":30,"page":25},"Technologies","/en/docs/technologies","en/1.docs/2.technologies",[31,35,39,43,47],{"title":32,"path":33,"stem":34,"children":-1},"Nextcloud","/en/docs/technologies/nextcloud","en/1.docs/2.technologies/1.nextcloud",{"title":36,"path":37,"stem":38,"children":-1},"Matrix / Element","/en/docs/technologies/matrix","en/1.docs/2.technologies/2.matrix",{"title":40,"path":41,"stem":42,"children":-1},"ONLYOFFICE","/en/docs/technologies/onlyoffice","en/1.docs/2.technologies/3.onlyoffice",{"title":44,"path":45,"stem":46,"children":-1},"Ubuntu Linux","/en/docs/technologies/ubuntu","en/1.docs/2.technologies/4.ubuntu",{"title":48,"path":49,"stem":50,"children":-1},"Keycloak","/en/docs/technologies/keycloak","en/1.docs/2.technologies/5.keycloak",{"id":52,"title":53,"authors":54,"badge":60,"body":62,"date":396,"description":397,"extension":398,"faq":399,"howto":417,"image":451,"meta":453,"navigation":454,"path":455,"seo":456,"stem":457,"__hash__":458},"posts_en/en/3.blog/19.cyber-resilience-act-september-2026-microsoft-smes-public-sector.md","Cyber Resilience Act – What German SMEs and public bodies must demand from Microsoft and their software suppliers from 11 September 2026",[55],{"name":56,"to":57,"avatar":58},"europioneer Team","/",{"src":59},"/favicon.svg",{"label":61},"Cyber Resilience Act",{"type":63,"value":64,"toc":384},"minimark",[65,69,98,105,110,120,123,151,158,162,169,172,186,190,193,220,233,237,253,264,268,278,298,308,312,315,319,322,359,377,381],[66,67,53],"h1",{"id":68},"cyber-resilience-act-what-german-smes-and-public-bodies-must-demand-from-microsoft-and-their-software-suppliers-from-11-september-2026",[70,71,72,73,77,78,81,82,85,86,89,90,93,94,97],"p",{},"In ",[74,75,76],"strong",{},"ten weeks"," – on ",[74,79,80],{},"11 September 2026"," – the ",[74,83,84],{},"Cyber Resilience Act (CRA)"," reporting obligations under ",[74,87,88],{},"Article 14"," enter into force. From that date onwards, every manufacturer of products with digital elements must report actively exploited vulnerabilities and severe security incidents within ",[74,91,92],{},"24 hours"," through the ENISA ",[74,95,96],{},"Single Reporting Platform (SRP)",". The CRA is not fully applicable until 11 December 2027, but the reporting duty is the operational anchor that must reshape procurement practice in German SMEs, schools, and public bodies right now.",[70,99,100,101,104],{},"We take the situation at the start of July 2026 apart without drama: what Article 14 actually requires, why Microsoft falls into scope, which four contract clauses must be on every software purchase from now on, where the interlock with ",[74,102,103],{},"NIS2"," is untidy, and which sovereign fallback building blocks should be prepared before September.",[106,107,109],"h2",{"id":108},"what-article-14-cra-requires-from-11-september-2026","What Article 14 CRA requires from 11 September 2026",[70,111,112,113,115,116,119],{},"The ",[74,114,61],{}," (Regulation (EU) 2024/2847) entered into force on 10 December 2024. It obliges manufacturers of ",[74,117,118],{},"products with digital elements (PDE)"," – practically anything using a network connection directly or indirectly – to a defined level of security across the entire product lifecycle. On 11 June 2026, Chapter IV on the notification of conformity assessment bodies already applied. On 11 September 2026, the Article 14 reporting duties follow. All other duties – CE marking, secure-by-design, technical documentation – take effect on 11 December 2027.",[70,121,122],{},"Specifically, Article 14 requires four notifications for an actively exploited vulnerability:",[124,125,126,133,139,145],"ol",{},[127,128,129,132],"li",{},[74,130,131],{},"Early warning within 24 hours"," to the competent national CSIRT and ENISA via the SRP.",[127,134,135,138],{},[74,136,137],{},"Full notification within 72 hours"," with details on the attack pattern, affected products, and initial countermeasures.",[127,140,141,144],{},[74,142,143],{},"Final report within 14 days"," of a corrective measure becoming available.",[127,146,147,150],{},[74,148,149],{},"For severe incidents"," without active exploitation: final report within one month.",[70,152,153,154,157],{},"Fines for breaches of the reporting duty go up to ",[74,155,156],{},"EUR 15 million or 2.5 percent of worldwide group turnover",", whichever is higher.",[106,159,161],{"id":160},"why-microsoft-is-in-scope","Why Microsoft is in scope",[70,163,164,165,168],{},"The CRA applies to every manufacturer making PDEs available on the EU market, regardless of the manufacturer's location. Windows 11, Microsoft 365, Azure, Exchange Online, SharePoint, Teams, Copilot – all fall into scope. From 11 September 2026, Microsoft must report actively exploited vulnerabilities in these products to the competent CSIRT via the ENISA SRP within 24 hours. In Germany, that is the ",[74,166,167],{},"CERT-Bund"," at the BSI.",[70,170,171],{},"The operational consequence for customer companies is double-edged. On the upside: the BSI and ENISA learn about new attack campaigns earlier, and the national threat-intelligence picture improves. On the downside: the notification to ENISA does not mean customers receive a patch – or even an official customer communication – within 24 hours. The interval between report and patch availability is structurally not regulated by the CRA; it is defined only by the contractual relationship between manufacturer and customer. This is exactly where the procurement work begins.",[70,173,174,175,180,181,185],{},"If you combine the CRA reporting logic with the ",[176,177,179],"a",{"href":178},"/en/blog/microsoft-copilot-flex-routing","Flex Routing outside the EU Data Boundary"," documented in April 2026 and the existing ",[176,182,184],{"href":183},"/en/blog/cloud-act-2026","CLOUD Act access situation",", you see the structural problem: a US parent decides reporting timing, patch prioritisation, and customer communication. A European customer relies on communication chains it neither controls nor negotiates.",[106,187,189],{"id":188},"four-contract-clauses-that-must-now-enter-every-software-purchase","Four contract clauses that must now enter every software purchase",[70,191,192],{},"German procurement practice must adopt four new standard clauses from July 2026. They do not replace existing IT-security clauses, they supplement them.",[194,195,196,202,208,214],"ul",{},[127,197,198,201],{},[74,199,200],{},"Pass-through obligation."," The manufacturer informs the customer of CRA reports affecting its products within a contractually defined deadline – 48 hours after its own ENISA report is customary. Without this clause, the customer company first learns from general media that a product in use is affected.",[127,203,204,207],{},[74,205,206],{},"Patch SLA for actively exploited vulnerabilities."," Maximum interval between ENISA notification and availability of a corrective measure. Realistic values are 14 days for critical vulnerabilities and 30 days for high. Shorter periods are negotiable with hyperscalers, often not with on-premises software.",[127,209,210,213],{},[74,211,212],{},"Secure-by-design warranty."," The manufacturer contractually warrants that its product will meet Annex I CRA requirements by 11 December 2027 and that CE marking with conformity assessment is documented. Without this warranty, the customer takes on product-liability risk if the manufacturer misses the deadline.",[127,215,216,219],{},[74,217,218],{},"End-of-life support rule."," The CRA requires security updates over the expected lifetime, at least five years. The contract must fix the exact support duration, extension options, and communication channels at EoL.",[70,221,222,223,227,228,232],{},"These clauses are not an academic exercise. ",[176,224,226],{"href":225},"/en/blog/bsi-it-grundschutz-microsoft-365","BSI IT-Grundschutz"," already requires structured supplier governance today, and the ",[176,229,231],{"href":230},"/en/blog/dora-microsoft-365-exit-strategy-banks-2026","DORA framework for the financial sector"," demands exit strategies for critical ICT third parties. The CRA now gives the same practice a third legal frame, aimed at the same core.",[106,234,236],{"id":235},"special-case-schools-and-public-bodies","Special case: schools and public bodies",[70,238,239,240,243,244,248,249,252],{},"For ",[74,241,242],{},"school authorities, municipalities, and Land-level agencies"," the CRA situation is doubly tight. First, procurement rules under GWB, VgV, and UVgO increasingly demand contractual coverage of IT-security requirements. A tender without CRA-compliant clauses is challengeable from September 2026. Second, the ",[176,245,247],{"href":246},"/en/blog/cada-eu-tech-sovereignty-package-public-sector-2026","Cloud and AI Development Act (CADA)"," has required sovereignty tiers since 3 June 2026. For ",[74,250,251],{},"CADA tier 3"," – European ownership, no US sub-processors – Microsoft is structurally unqualified. For tiers 1 and 2, the CRA clauses are mandatory but negotiable.",[70,254,239,255,258,259,263],{},[74,256,257],{},"schools",", the data-protection layer is added. The German Data Protection Conference continues to classify ",[176,260,262],{"href":261},"/en/blog/microsoft-365-schools","Microsoft 365 in schools"," as not legally compliant. Whoever additionally fails to lock the CRA clauses into the contract now amplifies the exposure of their procurement decision. A school authority signing a new Microsoft framework agreement in 2026 without CRA clauses will have to defend that choice in a 2028 audit.",[106,265,267],{"id":266},"interlock-with-nis2-and-gdpr","Interlock with NIS2 and GDPR",[70,269,270,271,273,274,277],{},"The new CRA reporting logic layers on top of existing duties from ",[74,272,103],{}," and ",[74,275,276],{},"GDPR"," – it replaces none. When Microsoft reports a Windows vulnerability through the SRP and an essential or important NIS2 entity sees that vulnerability actively exploited in its network, three parallel notifications become due:",[124,279,280,286,292],{},[127,281,282,285],{},[74,283,284],{},"CRA notification"," by Microsoft to ENISA (not by the user).",[127,287,288,291],{},[74,289,290],{},"NIS2 notification"," by the deploying company to the BSI – 24-hour first, 72-hour full, 30-day final notification.",[127,293,294,297],{},[74,295,296],{},"GDPR notification"," if personal data is affected, to the Land data-protection authority – 72 hours.",[70,299,300,301,307],{},"This is the practical shape of the ",[74,302,303],{},[176,304,306],{"href":305},"/en/blog/nis2-gdpr-microsoft-paradox","Microsoft paradox in NIS2 and GDPR",": the reporting burden sits with the deploying company, the information sits with the manufacturer. Whoever does not lock the pass-through duty contractually has a 24-hour reporting deadline based on publicly available attack signals – a systemic problem.",[106,309,311],{"id":310},"from-zero-to-a-cra-ready-supplier-register-in-ten-days","From zero to a CRA-ready supplier register in ten days",[70,313,314],{},"The HowTo section in the frontmatter of this post lays out a concrete ten-day path. Starting on 15 July 2026 gets the register with the ten most critical suppliers in place by the end of July and leaves buffer for renegotiation and internal runbooks until 11 September. Starting only in late August lands you in the deadline without documented clauses.",[106,316,318],{"id":317},"sovereign-building-blocks-as-a-fallback","Sovereign building blocks as a fallback",[70,320,321],{},"The CRA does not exclude US software. It only requires that such software be CRA-compliant. For critical core functions, building sovereign fallback blocks is still recommended. Four realistic replacements:",[194,323,324,333,342,348],{},[127,325,326,332],{},[74,327,328],{},[176,329,331],{"href":330},"/en/blog/nextcloud-vs-onedrive-sharepoint","Nextcloud for SharePoint and OneDrive"," – German provider, on-premises or with a European managed hoster, CRA compliance through the European manufacturer chain easier to evidence.",[127,334,335,341],{},[74,336,337],{},[176,338,340],{"href":339},"/en/blog/microsoft-teams-alternative","Element and Matrix for Teams"," – federation protocol, open standard, European providers with a direct CRA contact.",[127,343,344,347],{},[74,345,346],{},"openDesk for Microsoft 365"," – bundle by ZenDiS based on open source, designed for public administration but usable for SMEs.",[127,349,350,353,354,358],{},[74,351,352],{},"Aleph Alpha or Mistral for Azure OpenAI"," – sovereign LLM endpoints, see also the ",[176,355,357],{"href":356},"/en/blog/eu-ai-act-microsoft-copilot-smes-august-2026","AI Act consequences from 2 August 2026",".",[70,360,361,362,366,367,371,372,376],{},"We help SMEs, school authorities, and public bodies combine CRA contract review, supplier renegotiation, and fallback setup. ",[176,363,365],{"href":364},"/en/contact","Get in touch"," if the supplier register should be in place by the end of July, see the ",[176,368,370],{"href":369},"/en/alternativen","European alternatives"," we run, and compare ",[176,373,375],{"href":374},"/en/pricing","managed hosting prices"," with your current framework agreement.",[106,378,380],{"id":379},"bottom-line","Bottom line",[70,382,383],{},"11 September 2026 does not change software procurement law but the operational practice behind it. A framework agreement without pass-through obligation, patch SLA, secure-by-design warranty, and end-of-life support rule is a documented compliance risk from that date. Whoever confronts the ten most critical suppliers once in a structured way by the end of July uses the summer for negotiation and September for live operation. For the three to five positions where Microsoft cannot or will not deliver the clauses, the sovereign fallback should sit in the drawer as a prepared option.",{"title":385,"searchDepth":386,"depth":386,"links":387},"",2,[388,389,390,391,392,393,394,395],{"id":108,"depth":386,"text":109},{"id":160,"depth":386,"text":161},{"id":188,"depth":386,"text":189},{"id":235,"depth":386,"text":236},{"id":266,"depth":386,"text":267},{"id":310,"depth":386,"text":311},{"id":317,"depth":386,"text":318},{"id":379,"depth":386,"text":380},"2026-07-07T00:00:00.000Z","On 11 September 2026 the CRA reporting obligations kick in. What German SMEs, school authorities, and public bodies must now lock into contracts and where Microsoft cannot structurally deliver.","md",[400,403,406,409,412],{"q":401,"a":402},"What concretely changes on 11 September 2026 under the Cyber Resilience Act?","From 11 September 2026, the reporting obligations under Article 14 CRA apply. Manufacturers of products with digital elements – operating systems, cloud software, IoT devices, business applications – must report actively exploited vulnerabilities and severe security incidents through the ENISA Single Reporting Platform (SRP). An early warning is due within 24 hours of becoming aware, a full notification within 72 hours, and a final report no later than 14 days after a corrective measure is available for exploited vulnerabilities, or within one month for severe incidents. The other CRA obligations – CE marking, conformity assessment, secure-by-design – only apply from 11 December 2027.",{"q":404,"a":405},"Does the CRA apply to Microsoft even though Microsoft is headquartered in the US?","Yes. The CRA applies to every manufacturer that makes products with digital elements available on the EU internal market, regardless of place of establishment. From 11 September 2026, Microsoft must report Windows, Microsoft 365, and Azure vulnerabilities through the ENISA SRP as soon as they are actively exploited. For customers, waiting for Patch Tuesday is now flanked by law, but the operational gap between disclosure and patch availability does not close automatically. A 24-hour early-warning window does not mean customers receive a fix within 24 hours.",{"q":407,"a":408},"Are SMEs themselves subject to CRA reporting duties as users?","No. The reporting duties under Article 14 CRA fall exclusively on the manufacturer. A 40-person craft business using Microsoft 365 does not report incidents through the ENISA SRP. But the deploying company remains subject in parallel to NIS2, GDPR, and depending on sector DORA or BSI IT-Grundschutz. For essential and important entities under NIS2, the 24-hour early and 72-hour full notifications to the BSI continue to apply. The manufacturer's CRA notification complements those but replaces none.",{"q":410,"a":411},"What counts as an \"exploited vulnerability\" under the CRA?","Under Article 3 CRA, a vulnerability is considered actively exploited as soon as there is credible evidence of a malicious attack on a real system – a single documented attack is enough. Pure proof-of-concept exploits without documented misuse are not reportable. For Microsoft, this means zero-day vulnerabilities in Exchange, SharePoint, or Azure Active Directory, once a threat-intelligence team documents an actual attack, must be reported to the ENISA SRP within 24 hours from 11 September 2026.",{"q":413,"a":414},"Which contract clauses must an SME add to software procurement right now?",{"Four clauses become mandatory procurement checks":415},{" First, a pass-through obligation":416},"the manufacturer informs the customer of CRA reports affecting their systems within a contractually fixed deadline. Second, a patch SLA for actively exploited vulnerabilities with a maximum interval between report and patch availability. Third, a warranty that the manufacturer will meet Annex I CRA secure-by-design requirements by 11 December 2027 with documented CE marking. Fourth, a rule on end-of-life support – the CRA requires security updates over the expected product lifetime, at least five years.",{"name":311,"description":418,"totalTime":419,"steps":420},"A pragmatic path for a 30- to 250-person SME to have contractual and operational cover by 11 September 2026.","P10D",[421,424,429,432,437,440,443,448],{"name":422,"text":423},"Build the software supplier inventory","On days 1 and 2 tabulate every software supplier with product name, version, use area, and contract counterparty. Typical entries are operating systems, office suite, ERP, CRM, HR, collaboration, VPN, backup, IoT devices in production. Each entry receives a business-criticality priority.",{"name":425,"text":426},"Test CRA applicability",{"On day 3 clarify per supplier whether the product falls under the CRA":427},{" Rule of thumb":428},"anything with direct or indirect network capability is a product with digital elements. Pure open-source components without commercial distribution are exempt, commercial open-source distributions are not. For US suppliers also check whether a European branch is nominated as CRA contact point.",{"name":430,"text":431},"Draft the clause template","On day 4 formulate a four-point contract clause – pass-through obligation, patch SLA, secure-by-design warranty, end-of-life support. The clause enters the standard contract and all renewals from 1 August 2026. Prepare an addendum for existing contracts.",{"name":433,"text":434},"Contact critical suppliers",{"On days 5 and 6 confront the ten most critical suppliers with a structured questionnaire":435},{" Questions are":436},"Who is your CRA contact in the EU? Through which channel are CRA reports forwarded to customers? What patch SLA applies to actively exploited vulnerabilities? For how long do we receive security updates? Answers feed into the inventory.",{"name":438,"text":439},"Align internal incident response with the CRA window","On day 7 review the existing incident response plan. What happens when Microsoft sends a CRA early warning to ENISA on a Wednesday at 22:00 and Patch Tuesday is two weeks away? Who inside your own house responds within what deadline with what mitigations – WAF rule, feature disablement, network isolation? The answer sits as a runbook in the DMS.",{"name":441,"text":442},"Interlock the NIS2 reporting process","On day 8 align your NIS2 reporting logic with the new CRA situation. If a manufacturer-reported vulnerability is actively exploited in your own operations, a parallel 24-hour first notification to the BSI is due. Responsibilities, communication channels, and forms per channel go into a matrix.",{"name":444,"text":445},"Name sovereign fallback building blocks",{"On day 9 document a sovereign fallback per critical Microsoft product that can be activated in an emergency":446},{" Examples":447},"Nextcloud for SharePoint, Element/Matrix for Teams, openDesk for Microsoft 365. The fallback does not go live, but is prepared – account setup, training plan, rollout blueprint.",{"name":449,"text":450},"Consolidate and sign off the audit binder","On day 10 merge the supplier inventory, the questionnaire returns, the clause template, the revised incident plan, the NIS2 matrix, and the fallback documentation into a single audit binder. File it in the DMS with a version number, signed off by management. This binder is the answer when the BSI or a NIS2 auditor asks about CRA readiness.",{"src":452},"https://images.unsplash.com/photo-1550751827-4bd374c3f58b?w=1200&q=80",{},true,"/en/blog/cyber-resilience-act-september-2026-microsoft-smes-public-sector",{"title":53,"description":397},"en/3.blog/19.cyber-resilience-act-september-2026-microsoft-smes-public-sector","o0WPhDTQCGb9h_e_kCxPpIzO8K-Ksy415tW2l3w9M1Q",[460,464],{"title":461,"path":356,"stem":462,"description":463,"children":-1},"EU AI Act – What German SMEs must document for Microsoft Copilot by 2 August 2026","en/3.blog/18.eu-ai-act-microsoft-copilot-smes-august-2026","On 2 August 2026 the EU AI Act's GPAI obligations kick in. What SMEs must now document for Microsoft Copilot and which sovereign alternatives hold up.",{"title":465,"path":466,"stem":467,"description":468,"children":-1},"Nextcloud for SMEs – The Secure Alternative to OneDrive and SharePoint","/en/blog/nextcloud-for-smes","en/3.blog/2.nextcloud-for-smes","Nextcloud provides everything SMEs need for file management, team collaboration, and communication — on their own servers, GDPR-compliant.",1784618209809]