Smart manufacturing is becoming software-defined. Industrial controllers, edge gateways, robotics, machine-vision systems, cloud platforms, and remote maintenance tools now run on AI-driven decisions and constantly exchange data and software updates. That shift changes the risk profile entirely.
For European citizens, the risk goes beyond factory downtime. A vulnerable product can affect worker safety, product quality, personal data, essential supply chains, and trust in connected infrastructure.
As factories adopt AI, cybersecurity becomes part of product safety and public trust, not a technical detail added after deployment.
The EU market is moving from AI experimentation to accountable adoption
AI adoption is accelerating across Europe. Eurostat reports that 20.0% of EU enterprises with 10 or more employees used at least one AI technology in 2025, compared with 13.5% in 2024; manufacturing adoption reached 17.3%.
The message for industrial leaders is direct: AI adoption must scale with security, traceability, and operational resilience.
The EU Cyber Resilience Act (CRA) turns that responsibility into product requirements. It covers many hardware and software products with digital elements placed on the EU market. Its vulnerability and incident reporting duties apply from 11 September 2026, while the main obligations apply from 11 December 2027.
Manage CRA requirements as an engineering workflow: assess risks, embed security, test, document dependencies, manage vulnerabilities, and provide updates throughout the support period. Build compliance evidence continuously rather than at the end.
AI-native software development helps when AI is used across the engineering lifecycle, not just as a coding assistant. Instead of separate hand-offs, it connects three continuous activities: frame, build, and verify.

Image: The three phases are not sequential hand-offs — they share information continuously, and what testing learns feeds back into how the next requirement is framed.
Mapping the AI-Native SDLC to CRA Compliance
| Frame | Build | Verify | Operate |
|---|---|---|---|
| Define product risks, security objectives, boundaries, and CRA requirements. | Apply secure development, approved dependencies, SBOM updates, and traceable changes. | Automate testing and vulnerability management, supported by human review and compliance evidence. | Monitor products, manage disclosures and patches, and maintain security throughout the support period. |
For smart manufacturers, Cyber Resilience Act compliance means embedding security across the entire product lifecycle. AI-native software development can strengthen this approach by connecting development, verification, and operations through secure-by-design software development, supply-chain transparency, and human oversight.
Why Product Cybersecurity Is Becoming a Manufacturing Requirement
As IT and OT converge, cybersecurity weaknesses can impact production and physical operations. Effective industrial IoT security must address availability, safety, recovery, and access while aligning engineering and plant operations. IT and OT convergence creates new cybersecurity risks.
Smart factories connect controllers, sensors, robotics, cloud services, and remote-access tools, expanding the attack surface. Smart manufacturing cybersecurity must therefore protect products, software updates, interfaces, and the operational environments in which they run.
Connected products can remain in service for years, making product lifecycle security essential. Manufacturers need visibility into deployed products and their components to manage vulnerabilities and deliver secure updates. The EU Cyber Resilience Act (CRA) reinforces this lifecycle approach, making cybersecurity an ongoing responsibility throughout a product’s operational life.
Compliance requirements grow as manufacturing becomes software-defined and AI-powered
Manufacturing already operates within established safety, quality, and regulatory requirements. As products and production environments become software-defined, an additional layer of software-related safety, verification, traceability, and lifecycle requirements is introduced.
When that software becomes AI-powered, manufacturers must account for another layer of obligations, including the EU AI Act and data-protection requirements such as GDPR. Cybersecurity and operational resilience add further responsibilities, with the EU Cyber Resilience Act (CRA) bringing secure-by-design, vulnerability management, reporting, and lifecycle security into the product engineering equation.
The challenge is therefore cumulative: manufacturers are not replacing one compliance framework with another; they are adding software, AI, data-protection, cybersecurity, and resilience requirements to processes that must still satisfy existing industrial safety and functional obligations.
Taking all these dimensions into account within established engineering processes can make the transition toward Industry 5.0 complex and difficult to accelerate.
Calsoft addresses this challenge by bringing manufacturing-domain expertise together with machine- and AI-powered engineering, helping manufacturers design, develop, functionally test, secure, and deploy compliant frameworks in the actual manufacturing environment in approximately one-third of the classical development time, while maintaining strong human-in-the-loop oversight and control across critical engineering and governance decisions.
For smart-manufacturing products, this means embedding several disciplines into engineering:
- Risk assessment and secure-by-design and secure-by-default decisions before production.
- Vulnerability handling, coordinated disclosure, security updates and a defined support period.
- Technical documentation, component traceability and software bill of materials (SBOM) information to support supply-chain visibility.
- Conformity assessment, an EU Declaration of Conformity and CE marking where applicable.
- Fast, structured reporting through the CRA Single Reporting Platform when qualifying vulnerabilities or incidents are identified.
Why AI-native software development is a strong fit
AI changes the software lifecycle by making context available earlier and feedback faster. With AI-native software development, teams can connect requirements with architecture, source code, test coverage, runtime signals, and known vulnerabilities. This helps identify security gaps earlier, strengthen AI-generated code security, and maintain traceability as software and connected products evolve.
Traditional development often treats requirements, coding, testing, and compliance as separate hand-offs. AI-native software development changes the operating model. AI is used to understand and connect the whole engineering lifecycle, while people retain responsibility for decisions, risk acceptance, and accountability.
Where AI-Native Development Meets the EU Cyber Resilience Act
1. Frame requirements in full context
A requirement should define more than what a machine or application must do. It should also capture system structure, business process, runtime instrumentation, security controls, compliance obligations, and safe maintenance. When these dimensions are specified together, an AI system can reason about how a functional change affects cybersecurity, evidence and operations from the beginning.
2. Build code, tests and change intelligence together
AI-assisted development can generate software alongside structural, functional, and security tests. It can also create a change-impact map: which components are likely to be affected when a model, service, device integration, or workflow changes. This makes incremental updates more controlled and reduces the risk of breaking a certified or safety-relevant capability.
3. Test continuously and proportionately
Testing becomes a continuous capability rather than a final gate. AI can combine unit, integration and system testing with workflow, contextual and security testing. It can prioritise the highest-value checks for each change, expanding verification when the influence of a change is broad and focusing it when the risk is contained.
4. Operate with evidence and controlled evolution
Observability, vulnerability response, patch governance, and compliance evidence should remain connected after deployment. This supports the CRA’s lifecycle approach and helps engineering teams show what changed, why it changed, how it was tested, and how users are protected.
How Calsoft turns the model into an engineering practice
Calsoft applies AI across the full product engineering lifecycle, not as an isolated product feature, but to deliver advanced, secure, and compliant customer solutions.
Calsoft brings these layers together into a unified engineering approach. By combining manufacturing-domain understanding with machine- and AI-powered development, automation, testing, and governance, Calsoft can work with manufacturers to design, develop, and deploy a fully secure, compliant, and functionally tested framework in situ in approximately one-third of the classical development time.
This acceleration does not remove human accountability. Strong human-in-the-loop oversight and control remain integral to requirements, architecture, risk decisions, validation, compliance evidence, and deployment, enabling manufacturers to use AI for engineering speed while retaining the governance required for safety-critical and regulated environments.
- Business and software engineering evolve together: user workflows, operational goals and technical architecture are treated as one system.
- Compliance, governance and security are built into requirements, architecture, testing and delivery; not added later or treated as an afterthought.
- Complete end-to-end solutions cover discovery, architecture, UX, development, integration, validation, deployment and lifecycle management.
- A unified engineering approach gives users visibility across business and engineering processes, supporting collaboration, governance and faster, safer innovation.
- Domain expertise is combined with AI-driven engineering practices to build enterprise-grade solutions for complex industrial environments.
The outcome: safer innovation with public value
For European manufacturers, the opportunity is not simply to produce software faster. It is to create industrial products that remain secure, explainable, maintainable, and trustworthy as they evolve. An AI-native engineering model helps make that possible by turning compliance and cybersecurity into living properties of the product lifecycle. Calsoft’s AI, cloud, infrastructure, and product-engineering capabilities are designed to help customers move from fragmented delivery to unified engineering control. The goal is to help manufacturers leap toward Industry 5.0 without treating functional safety, AI governance, data protection, cybersecurity, and resilience as separate afterthoughts.
Frequently Asked Questions
What Is the EU Cyber Resilience Act?
The EU Cyber Resilience Act sets cybersecurity requirements for products with digital elements throughout their lifecycle.
Does the Cyber Resilience Act Apply to Software?
Yes. It applies to software products with digital elements placed on the EU market.
Does the CRA Apply to Smart Manufacturing Products?
Yes. It may apply to connected machines, embedded software, edge gateways, and industrial applications.
How Does AI-Native Software Development Support CRA Compliance?
It connects secure design, coding, testing, SBOM management, vulnerability management, and security updates.
Does AI-Generated Code Create CRA Cybersecurity Risks?
Yes. It may introduce insecure code or vulnerable dependencies. Human review, testing, and security scanning are essential.
Why Is SBOM Important for CRA Compliance?
An SBOM lists software components and versions, helping manufacturers identify and fix vulnerabilities faster.
What Are the CRA Deadlines for Manufacturers?
Reporting duties begin on 11 September 2026, while the main CRA obligations apply from 11 December 2027.
How Can Manufacturers Prepare for CRA Compliance?
Assess product risks, adopt secure-by-design development, implement AI DevSecOps, maintain an SBOM, manage vulnerabilities, and document evidence continuously.

