EU Cyber Resilience Act part two: Updates & Impracticalities - Bert Hubert's writings
a day ago
- The CRA's handling of third-party components is ambiguous, requiring 'due diligence' but with wide interpretation that could range from minimal checks to full compliance.
- The essential cybersecurity requirement 'no known vulnerabilities' (dropping 'exploitable') is impractical and could lead to billions in costs, making it risky to ship products to Europe.
- Standards from CEN-CENELEC are needed to clarify requirements, but no agreed standard is expected for years, leaving manufacturers dependent on non-existent or insufficient notified bodies.
- Without standards or auditing capacity by 2027, new products with digital elements may be barred from the EU single market, risking a freeze on innovation and market entry.
- The article emphasizes the need for clearer guidance to avoid stifling innovation and ensure the CRA is workable.