Hasty Briefsbeta

Bilingual

EU Cyber Resilience Act part two: Updates & Impracticalities - Bert Hubert's writings

a day ago
  • The CRA's handling of third-party components is ambiguous, requiring 'due diligence' but with wide interpretation that could range from minimal checks to full compliance.
  • The essential cybersecurity requirement 'no known vulnerabilities' (dropping 'exploitable') is impractical and could lead to billions in costs, making it risky to ship products to Europe.
  • Standards from CEN-CENELEC are needed to clarify requirements, but no agreed standard is expected for years, leaving manufacturers dependent on non-existent or insufficient notified bodies.
  • Without standards or auditing capacity by 2027, new products with digital elements may be barred from the EU single market, risking a freeze on innovation and market entry.
  • The article emphasizes the need for clearer guidance to avoid stifling innovation and ensure the CRA is workable.