Skip to content

INDUSTRY · Defence

Defence: system safety and cybersecurity readiness

Defence programmes sit partly outside CRA scope but face equally demanding, often stricter, national safety and security assurance regimes.

LAST REVIEWED

Regulatory picture

The Cyber Resilience Act explicitly excludes products developed or exclusively adapted for military purposes or classified national security use, recognising that defence procurement already operates under dedicated national assurance frameworks. Where a defence supplier also sells a civilian or dual-use variant of a product, that variant can fall fully within CRA scope even though the military variant does not. Safety assurance in defence typically follows national or NATO-aligned standards such as the UK's Def Stan 00-56 (safety management), US MIL-STD-882 (system safety), or platform-specific certification regimes for airborne, maritime and land systems, generally built on the same functional safety principles found in IEC 61508.

NIS2 also has defence relevance where a defence contractor's own infrastructure or supply chain falls within a covered sector, and many defence primes now flow down cybersecurity requirements contractually to suppliers regardless of direct regulatory scope.

Typical engineering challenges

  • Determining, product by product, whether the military exclusion genuinely applies, particularly for dual-use components and export variants.
  • Reconciling long procurement and support lifecycles, often decades, with software and component obsolescence and evolving cybersecurity expectations.
  • Maintaining a defensible safety and security case across multiple subcontractors with differing internal standards and evidence formats.
  • Managing classified or export-controlled information constraints alongside the transparency that safety and security assurance normally requires.
  • Integrating COTS (commercial off-the-shelf) components, which increasingly carry their own CRA obligations, into systems assured under separate defence-specific regimes.

How CRA interacts with sector rules

For a defence organisation with a mixed portfolio, the practical task is classification: establishing per product line whether the CRA military exclusion applies, documenting the basis for that determination, and applying full CRA scoping to anything that does not qualify. Where COTS components are integrated into military systems, the defence integrator should still understand the CRA obligations of its commercial suppliers, since a supplier's vulnerability handling and support commitments directly affect the integrator's own long-term support case.

What a typical engagement covers

  • Scoping to confirm CRA applicability or exclusion per product line, with a documented rationale.
  • Safety case structuring aligned to the relevant national or platform standard, integrating cybersecurity risk where it affects safety functions.
  • Supplier and component assurance review across a multi-tier defence supply chain.
  • Long-lifecycle support planning: vulnerability handling, obsolescence management and evidence retention across decades-long programmes.

Frequently asked questions

Are all defence products exempt from the CRA?

No. Only products developed or exclusively adapted for military purposes, or classified for national security, are excluded. Dual-use products and civilian variants of defence technology can fall fully within CRA scope, and the exclusion should be assessed and documented per product line rather than assumed for an entire portfolio.

What safety standard applies to defence systems instead of IEC 61508 directly?

Many defence programmes use domain-specific standards derived from or aligned with IEC 61508 principles, such as Def Stan 00-56 in the UK or MIL-STD-882 in the US, alongside platform-specific certification regimes for airborne, land or maritime systems.

Do NATO or national security clearance requirements conflict with CRA vulnerability reporting?

For products genuinely within the military exclusion, CRA reporting duties do not apply. For dual-use or civilian products handled by cleared personnel, reporting processes need to be designed so that they meet CRA timelines without breaching separate classification or export control obligations.

How does obsolescence management relate to CRA-style vulnerability handling?

Defence programmes already manage obsolescence over long support periods; extending that process to include active vulnerability monitoring and remediation planning for digital components is a natural extension rather than a separate discipline, and is expected practice even outside formal CRA scope.