The Cyber Resilience Act forces manufacturers of digital products to report actively exploited vulnerabilities within 24 hours and severe incidents within 72 hours. That kind of speed needs people who can monitor, triage, and write regulatory reports under pressure. Most tech companies don't have enough of them yet, and that's why hiring for these roles has picked up fast.
You've got a security team. Maybe a decent one. But ask them to file a compliant incident report to a regulator within 24 hours, every time, without fail, and you'll find out fast whether your setup actually holds up.
That's the situation a lot of CTOs and engineering leads are in right now. The Cyber Resilience Act doesn't care whether you're ready. It just starts the clock. And the people who can run that clock without missing a deadline are suddenly a lot harder to find than they were a year ago.