For others who might have a similar thing to ours, updating a firmware through a secure channel (best practice, TLS, per-device private keys) - we don't separately sign the firmware because with the secure link, it's redundant, and it's redundant in the bad way of being "more of the exact same thing" - if we fail so badly that we leak our own CA key, or we accidentally store and leak device private keys, then the exact same failure would as easily leak the firmware signing keys.
Claude seems to confirm ours is sufficient:
On firmware signing, EN 18031 agrees with you. Requirement SUM-2 asks that only software with valid integrity and authenticity gets installed. It lists four accepted implementation categories: digital signature, secure communication mechanism, access control, and "other". An update accepted only over a mutually authenticated TLS link fits "secure communication". The Commission rejected the signature-free categories only for part -3 (financial assets), which is not your case. So there is no separate signing key requirement here.
Much of that video is clearly BS. It is a sales pitch for a CPU manufacturer. Cound how often the guy says "basically" - always a clue to no clue

He also says open source will need to comply, which of course will never happen.
I simply do not believe Brussels would mandate the use of anti tamper technology since the vast majority of microcontrollers would be unsuitable.
Also they cannot mandate upgrades for x years because many firms are not around for that long

Sounds like another EU BS which will get ignored, but not before the Americans first fall over laughing and second get scared of selling products into Europe - just like loads of websites block European IP ranges due to "GDPR".
One way around it is to not offer OTA, presumably. But it seems an upgrade path is mandatory if there is any possible internet connection. One issue is TLS is a huge piece of code, and don't you need secure local storage for the update validation? A TLS client does not to be secure to access a server but this is a step beyond.
I simply do not believe Brussels would mandate the use of anti tamper technology
Simple: they don't.
I agree with you: very careful with generic statements from people who sell solutions. Before a solution can be sold, a problem needs to be sold.
Have to read the actual standards and figure out what applies case-by-case, and gladly we have LLMs these days to process through large amounts of text which formerly took days of human work.
It sounds like if you have a box with say ETH, then you need to a) publish known back doors and b) offer firmware upgrades (OTA or manual download) and these need some sort of validation, either against a stored key (and secure storage for that is not mandatory) or via a secure connection (and secure storage for the certificate(s) is also not mandatory).
Now what if you have a box which radiates UDP broadcast packets over WIFI. There is "no way" it can access the internet unless somebody replaces the firmware and turns the WIFI into a client.
Now what if that WIFI can be a client, via a config file entry which connects the WIFI to LWIP etc (the above UDP functionality runs the WFM200 directly and does not use LWIP) but that config file can be edited only over a USB cable? But then the box is in a "config mode" and does not perform its normal function. Tricky?
Much of that video is clearly BS. It is a sales pitch for a CPU manufacturer. Cound how often the guy says "basically" - always a clue to no clue
He also says open source will need to comply, which of course will never happen.
I simply do not believe Brussels would mandate the use of anti tamper technology since the vast majority of microcontrollers would be unsuitable.
Also they cannot mandate upgrades for x years because many firms are not around for that long
Sounds like another EU BS which will get ignored, but not before the Americans first fall over laughing and second get scared of selling products into Europe - just like loads of websites block European IP ranges due to "GDPR".
One way around it is to not offer OTA, presumably. But it seems an upgrade path is mandatory if there is any possible internet connection. One issue is TLS is a huge piece of code, and don't you need secure local storage for the update validation? A TLS client does not to be secure to access a server but this is a step beyond.
Nah, it's not BS, it's called customer protection. This is not targeted towards your gadget that you sell a few thousands of.
They are targeting smart TVs, IP cameras, smart speakers, and Amazon alexas.
For too long, manufacturers got away with firmware that was cobbled together by a couple of grad students, and now by chatGPT. Full of security holes, and intrusive tracking. You can find ample evidence of smart devices taken over by the millions, and then used for botnet attacks. Or devices that stop working because "we changed the API and didn't update last year's gadget"
I think it's long overdue to set some legally required quality standards for software.
This is not targeted towards your gadget that you sell a few thousands of.
They are targeting smart TVs, IP cameras, smart speakers, and Amazon alexas.
For sure that is the intent but everybody gets caught up in this. You could be selling a 3 or 4 digit volume product into the industrial sphere, and your customers will be demanding EN18031 compliance. And a whole industry of "compliance consultants" and EN18031 certification bodies will grow up around this. And this pretty effectively buggers up small companies. The world is already full of compliance vermin, and ultra powerful compliance officers in every sizeable company.
For too long, manufacturers got away with firmware that was cobbled together by a couple of grad students, and now by chatGPT. Full of security holes, and intrusive tracking. You can find ample evidence of smart devices taken over by the millions, and then used for botnet attacks. Or devices that stop working because "we changed the API and didn't update last year's gadget"
Can you give actual examples of "2 grad students" and chatgpt designs which gave problems?
Most rented botnets are a) gaming browser extensions which the user deliberately installed and b) PCs infected via email borne viruses. The stuff about e.g. laser printers becoming bots is just theory.
There are no known actual cases of Alexa hacks, and for sure these boxes were not designed by chatgpt or a couple of grad students, because they have the potential of doing billion $ damage to the said company.
For sure that is the intent but everybody gets caught up in this. You could be selling a 3 or 4 digit volume product into the industrial sphere, and your customers will be demanding EN18031 compliance. And a whole industry of "compliance consultants" and EN18031 certification bodies will grow up around this. And this pretty effectively buggers up small companies. The world is already full of compliance vermin, and ultra powerful compliance officers in every sizeable company.
Three things that save your ass,
1)
as always, the regulation actually is not as limiting as salesmen of solutions make it sound like. Just read it and you'll find ways to deal with it.
2) no one is
really assessing your product to every letter. Accidental small omissions are fine. "Due diligence" does not equal perfection.
3) AI makes (1) actually possible even for small players. You may still need to pay for the standard so that AI can read all of it, but it saves a week of 8 hours / day reading, which is the actual cost for small players who have their hands full of other stuff.
This is not targeted towards your gadget that you sell a few thousands of.
They are targeting smart TVs, IP cameras, smart speakers, and Amazon alexas.
For sure that is the intent but everybody gets caught up in this. You could be selling a 3 or 4 digit volume product into the industrial sphere, and your customers will be demanding EN18031 compliance. And a whole industry of "compliance consultants" and EN18031 certification bodies will grow up around this. And this pretty effectively buggers up small companies. The world is already full of compliance vermin, and ultra powerful compliance officers in every sizeable company.
For too long, manufacturers got away with firmware that was cobbled together by a couple of grad students, and now by chatGPT. Full of security holes, and intrusive tracking. You can find ample evidence of smart devices taken over by the millions, and then used for botnet attacks. Or devices that stop working because "we changed the API and didn't update last year's gadget"
Can you give actual examples of "2 grad students" and chatgpt designs which gave problems?
Most rented botnets are a) gaming browser extensions which the user deliberately installed and b) PCs infected via email borne viruses. The stuff about e.g. laser printers becoming bots is just theory.
There are no known actual cases of Alexa hacks, and for sure these boxes were not designed by chatgpt or a couple of grad students, because they have the potential of doing billion $ damage to the said company.
There is plenty of evidence that smart devices or routers getting hacked, this is just one of them.
https://en.wikipedia.org/wiki/Mirai_(malware)If you think that the IoT devices are programmed by seasoned veterans, then you never seen a startup or tried to hire someone who's main skill is pyhton.
Can you give actual examples of "2 grad students" and chatgpt designs which gave problems?
I mean, mainstream media is nowadays full of reminders how a grandma, age 98, should be downloading and installing firmware updates to their home router every week, even though said grandma doesn't even have any idea what "home router" means.
The whole EEVblog DDoS attack was a good example of all sorts of hacked infra performing the attack. Maybe some of them were home routers grandma didn't update despite reading from newspapers that they need to.
I simply do not believe Brussels would mandate the use of anti tamper technology
Simple: they don't.
I agree with you: very careful with generic statements from people who sell solutions. Before a solution can be sold, a problem needs to be sold.
Have to read the actual standards and figure out what applies case-by-case, and gladly we have LLMs these days to process through large amounts of text which formerly took days of human work.
True. And way better than some random Youtube video from a self proclaimed expert. But I would advise to also bring in a legal expert as well. AI can and does overlook things.
But I would advise to also bring in a legal expert as well. AI can and does overlook things.
The classic compliance test houses and their consultation services would be better value than an outright lawyer, although with enough budget a legal team would be the next logical expansion.
But I would definitely combine compliance consultant + AI. Especially if you have to limit the consultant's scope to minimum due to cost constraints ("just take a quick look for 2000€" type of deal, which startups normally do). The consultant offers certain type of intuition AI doesn't do (also real-world experience with similar customers), and AI processes through the huge amount of text (you need to give any design documents / code etc. you have to an actual agent so that it reads your design AND the standard and reasons about it as a whole; generic ChatGPT session isn't worth much.)
Perhaps one way to avoid EN18031 is not connect it directly to the internet, if feasible.
Use air gap, "sneaker net" (USB sticks) to transfer data and fw updates.
Or a phone app that talks bluetooth to your device.
LoRaWAN might simplify things, move EN18031 problems to the LoRaWAN gateway.
I have not read the standard so the above could be BS.
There is plenty of evidence that smart devices or routers getting hacked, this is just one of them.
https://en.wikipedia.org/wiki/Mirai_(malware)
If you think that the IoT devices are programmed by seasoned veterans, then you never seen a startup or tried to hire someone who's main skill is pyhton.
Or you can buy devices with malware pre-installed:
Read This Before You Buy That TV Streaming Stick -
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/Brian has posted several articles about that topic.
Take Cisco as another example. They sell really expensive enterprise and carrier-grade boxes but still manage to add the same stupid security holes over and over again. Maybe it's profit optimization.
There's probably going to be EN18031 SoM's available, ready to internetify your product. Subscription only of course
Perhaps one way to avoid EN18031 is not connect it directly to the internet, if feasible.
Use air gap, "sneaker net" (USB sticks) to transfer data and fw updates.
Or a phone app that talks bluetooth to your device.
LoRaWAN might simplify things, move EN18031 problems to the LoRaWAN gateway.
I have not read the standard so the above could be BS.
The standard refers to connecting to the internet via other connections, which would imply that if you connect via Bluetooth to something that connects to the internet you are in scope for the CRA.
Also, there is some stuff in there about secure update deployment - i.e. making sure the update isn't tampered with
Neil
Perhaps one way to avoid EN18031 is not connect it directly to the internet, if feasible.
Use air gap, "sneaker net" (USB sticks) to transfer data and fw updates.
Or a phone app that talks bluetooth to your device.
LoRaWAN might simplify things, move EN18031 problems to the LoRaWAN gateway.
I have not read the standard so the above could be BS.
Nope. AFAIK any device having some form of connectivity falls under it. Actually, having a device connected to internet (directly or indirectly through some communication hub) is an advantage as it makes it easier to deploy mandated firmware updates as the user doesn't need to intervene.
The regulation is not about user convenience though.
And if the user has to download an update and manually install it, far fewer will be doing it, so there will be less need for tech support
Perhaps one way to avoid EN18031 is not connect it directly to the internet, if feasible.
Use air gap, "sneaker net" (USB sticks) to transfer data and fw updates.
Or a phone app that talks bluetooth to your device.
LoRaWAN might simplify things, move EN18031 problems to the LoRaWAN gateway.
I have not read the standard so the above could be BS.
Nope. AFAIK any device having some form of connectivity falls under it. [...]
Nope again: as I understood from the video (with the example of a simple fully stand-alone voltmeter),
any device with transistors working in non-linear region (my puny description of digital) falls under CRA regardless of its connectivity. A threat analysis has to be done even for the given example (like if someone hacks it and it shows a wrong voltage what is the potential for damage ?) and the development process has to consider that analysis.
Sure thing in EU the regulations grow thick and wide: chief of Dacia
says that the number of regulations has grown to big and calls for a pause.
She also says that the button that deactivates driver assistance systems is the most used button.
that the number of regulations has grown to big and calls for a pause.
AI accelerates this: regulators are able to come up with more and more regulations, which smaller and smaller companies are able to pass in shorter and shorter time, because AI reads whatever regulators wrote and implements it in 1/100th of the time humans would. The non-obvious flipside is: that means humans are not able to implement all the requirements anymore. Do we want that?
A lot of this regulation is
good, and it's also good it gets done. But the risk is, we are implementing stuff we don't fully understand, and we don't always know why. We are thus losing control, and we are losing simplicity, two good core values. AI is very good at details. And it also gets lost in the details.
I would like to see NorthGuy as some kind of safety backstop on global development of things. Like - "is this complexity truly needed"?
Perhaps one way to avoid EN18031 is not connect it directly to the internet, if feasible.
Use air gap, "sneaker net" (USB sticks) to transfer data and fw updates.
Or a phone app that talks bluetooth to your device.
LoRaWAN might simplify things, move EN18031 problems to the LoRaWAN gateway.
I have not read the standard so the above could be BS.
Nope. AFAIK any device having some form of connectivity falls under it. [...]
Nope again: as I understood from the video (with the example of a simple fully stand-alone voltmeter), any device with transistors working in non-linear region (my puny description of digital) falls under CRA regardless of its connectivity.
That video is to be ignored as it is the same sales pitch we got when emissions testing became mandatory. Most of it is BS. Get information from the regulatory body instead!
that the number of regulations has grown to big and calls for a pause.
AI accelerates this: regulators are able to come up with more and more regulations, which smaller and smaller companies are able to pass in shorter and shorter time,
Dacia is part of Renault which is not small and even Renault complains.
The non-obvious flipside is: that means humans are not able to implement all the requirements anymore. Do we want that?
Not all regulations are equal: for example a regulation requiring physiscal and similar controls for car standard functions is absolutedly welcome. Accomodation to a different car should not take more than a few minutes. With a Tesla for example I feel like I would need a few hours of training.
But a regulation that surrounds me with things that anoys me (and I become irritated when I forget to disable them) AND makes me pay for them ? Now that is not a good regulation. And the worst part is: everyone I spoke with felt the same way for quite a lot of time, yet in that time more of this regulations came and none (as I know of) went away. At some point its not that humans are not able to implement those regulations, its that humans are
not able to even follow those regulations. I do not understand why you said it is "non-obvious". The Brits have a saying: the less evolved is a country the more paperwork is required in that country.
But the risk is, we are implementing stuff we don't fully understand, and we don't always know why. We are thus losing control, and we are losing simplicity, two good core values. AI is very good at details. And it also gets lost in the details.
I would like to see NorthGuy as some kind of safety backstop on global development of things. Like - "is this complexity truly needed"?
To paraphrase Bruce Scheiner in the context of the topic: The first rule of security is that complexity is the biggest enemy of security. The second rule of security is that complexity is the biggest enemy of security.
I do not understand why you said it is "non-obvious".
The non-obvious part is that the AI makes it possible to keep following with the regulation, to make it
look like there is no overregulation.
Because normally, regulation is self-regulating (pun intended) - too much suffocates the economy / development, someone realizes that and gives a bit of slack.
But combining AI and overzealous regulators causes a non-obvious shift from human work, to AIs doing everything autonomously without much human monitoring, because humans don't have enough time to keep track of all the regulation. This already happens even if humans write the regulations: imagine how much worse it gets when they realize they can use AI to do it.
There is a fundamental imbalance: a regulator spending 5 minutes to write a sentence into a document can cost 5 weeks for a company. With regulators still human, and implementers now AI, this imbalance disappears. Feels good on surface, but the risk is regulatory capture by AI.
Brussels will always make regulation. That is their job. They cannot stop and will never stop.
There was a great video online (can't find it now) of a generously proportioned EU official called Seebohm saying (aviation context) "this is an area where there is no regulation, which is unacceptable, so we must create some".
It takes special talent to say that with a straight face.
Then again, generally the quality of EU regulation is good - most of it exists for good reasons, most of it is well-designed.
But of course regulation has bugs in it, any human product has. Usually unintended failures to see some corner case, and fixation on something else. Bureaucrats creating unnecessary rules on malice, or for their own job security, is a real potential issue but probably exaggerated in coffee room discussions.
The problem with regulations is that a small bug can cause large damage, if everyone has to follow the broken/unnecessary rule. But you also need to remember that it is entirely normal not to follow every rule to the letter. Everyone does that: small and large companies alike, and individuals. Very rarely you get any kind of sanctions of not following a stupid rule. Sometimes companies even choose to ignore the rules and pay fines.
And if your product is unsafe shit, you should make it good and safe even if there were no rules. Rules are needed to enforce actions on foul players who decline to act when they should.