Author Topic: Scope of EU Cyber Resilience Act  (Read 2207 times)

0 Members and 1 Guest are viewing this topic.

Offline SethGPITopic starter

  • Newbie
  • Posts: 5
  • Country: us
Scope of EU Cyber Resilience Act
« on: September 25, 2025, 03:57:45 pm »
I know there's an old "heads-up" thread from a few years ago on the topic of the EU's CRA.

Is anyone here any more of an expert on this legislation now? We do some embedded design without internet/cloud connectivity. However, in some instances, our products are used as inputs to industrial equipment/PLCs. These interfaces being analog 4-20mA (no HART) and variable frequency "digital" signals which are purely open-collector pulses for volumetric counting from a fluid flow meter. All communication is one-way, from our product into a PLC or equivalent machine. The products do have microcontrollers in them for calibration and linearization as well as various customer settings.

In recent discussions with a firmware house for future products, they mentioned that even our 4-20mA products will have to comply with the CRA to our surprise. Granted, this came from a director-level conversation. Looking in the legislation as an engineer and not a lawyer, there are some definitions of terms which make me think that our products would not need to be compliant, but there are also some terms and clauses that are vague enough that it could. For example, the PLC could be internet connected, and our products would be an input to this internet-connected device.

Of course for actual legal analysis we would need some legal council, but does anyone here have any familiarity with this legislation and its application in the embedded space?
 

Offline tszaboo

  • Super Contributor
  • ***
  • Posts: 9823
  • Country: nl
  • Current job: ATEX product design
Re: Scope of EU Cyber Resilience Act
« Reply #1 on: September 25, 2025, 04:12:39 pm »
As far as I know, for now, it's covered under the radio equipment directive, or RED. You can download the legislation from EUs website, and it will have an annex, listing all the applicable "harmonized standards". The legislation will tell you how you can get compliance with it.
You need to figure it out which standards are applicable to your products.
 

Online SiliconWizard

  • Super Contributor
  • ***
  • Posts: 17795
  • Country: fr
Re: Scope of EU Cyber Resilience Act
« Reply #2 on: September 25, 2025, 04:27:30 pm »
As I read it, it applies to anything potentially connected to a larger "network" - not necessarily directly the Internet.

That means pretty much anything with a LAN or WLAN connection, even if it never directly connects outside a LAN. I'll have to read it entirely though to figure out all the details. It's 81 freaking pages.

I don't much like this pile of regulations over regulations over regulations, but I think this article is interesting:
Quote
When products with digital elements reach the end of their support periods, in order to ensure that vulnerabilities
can be handled after the end of the support period, manufacturers should consider releasing the source code of such
products with digital elements either to other undertakings which commit to extending the provision of
vulnerability handling services or to the public. Where manufacturers release the source code to other undertakings,
they should be able to protect the ownership of the product with digital elements and prevent the dissemination of
the source code to the public, for example through contractual arrangements.
 

Offline tszaboo

  • Super Contributor
  • ***
  • Posts: 9823
  • Country: nl
  • Current job: ATEX product design
Re: Scope of EU Cyber Resilience Act
« Reply #3 on: September 25, 2025, 04:43:54 pm »
As I read it, it applies to anything potentially connected to a larger "network" - not necessarily directly the Internet.

That means pretty much anything with a LAN or WLAN connection, even if it never directly connects outside a LAN. I'll have to read it entirely though to figure out all the details. It's 81 freaking pages.

I don't much like this pile of regulations over regulations over regulations, but I think this article is interesting:
Quote
When products with digital elements reach the end of their support periods, in order to ensure that vulnerabilities
can be handled after the end of the support period, manufacturers should consider releasing the source code of such
products with digital elements either to other undertakings which commit to extending the provision of
vulnerability handling services or to the public. Where manufacturers release the source code to other undertakings,
they should be able to protect the ownership of the product with digital elements and prevent the dissemination of
the source code to the public, for example through contractual arrangements.
These regulations happen for a reason. The way I see it, it never happens proactively, it's always seem reactive. So some psychopath company decides to release products with built in default passwords, stealing data, having no security whatsoever, or provides 5 minutes of security updates to a phone that you are supposed to use for years.
It's consumer protection. And it usually makes sense. Otherwise we would have a complete wild west corpocracy, that always end up in some dystopia. Don't blame the EU, blame the company that made this nessesary.
 
The following users thanked this post: gmb42

Offline hamdi.tn

  • Frequent Contributor
  • **
  • Posts: 638
  • Country: tn
Re: Scope of EU Cyber Resilience Act
« Reply #4 on: November 23, 2025, 02:44:05 pm »
These regulations happen for a reason. The way I see it, it never happens proactively, it's always seem reactive. So some psychopath company decides to release products with built in default passwords, stealing data, having no security whatsoever, or provides 5 minutes of security updates to a phone that you are supposed to use for years.
It's consumer protection. And it usually makes sense. Otherwise we would have a complete wild west corpocracy, that always end up in some dystopia. Don't blame the EU, blame the company that made this necessary.

I'm sorry, this has nothing to do with the consumer protection, it's just protection for insurance compagnies, cyberattacks on large companies become recurrent events with serious consequences and costs, for now ,as far as i know, no legal basis to point the companies responsibilities when it come to preventing security issues. Now a cyberattack will become a legal debate and infinite amount of audits for each and hw/sw supplier to figure out who will pay the bill.

Soon insurance companies will add a new product that will have to pay so when everything fail (and most likely it will, as cyberattack prevention is mostly reactive to known vulnerabilities) and your product is somehow proven to be the entry point to the cyberattack, you can pay the lawyers and penalty of 15 millions euro or 2,5 % of your global income.

What this will do really is, kill small IoT suppliers and developer, they have to add the cost of the infrastructure and HR needed to maintain the documentation required by CRA and RED DA, the infrastructure to collect the security related data for their devices for a minimum of 10 years, the cost of tools to automate documentation production and software analysis, keep an eye on every known venerability and update the fw systematically... it's a bureaucratic nightmare.

 

Offline tszaboo

  • Super Contributor
  • ***
  • Posts: 9823
  • Country: nl
  • Current job: ATEX product design
Re: Scope of EU Cyber Resilience Act
« Reply #5 on: November 23, 2025, 06:42:45 pm »
What this will do really is, kill small IoT suppliers and developer, they have to add the cost of the infrastructure and HR needed to maintain the documentation required by CRA and RED DA, the infrastructure to collect the security related data for their devices for a minimum of 10 years, the cost of tools to automate documentation production and software analysis, keep an eye on every known venerability and update the fw systematically... it's a bureaucratic nightmare.
Let me get the word tinyest violin to play a sad song.
It's too easy to release any kind of software, which results bad software everywhere. Now at least there are some standards for it.
 

Offline hamdi.tn

  • Frequent Contributor
  • **
  • Posts: 638
  • Country: tn
Re: Scope of EU Cyber Resilience Act
« Reply #6 on: November 23, 2025, 08:17:36 pm »
What this will do really is, kill small IoT suppliers and developer, they have to add the cost of the infrastructure and HR needed to maintain the documentation required by CRA and RED DA, the infrastructure to collect the security related data for their devices for a minimum of 10 years, the cost of tools to automate documentation production and software analysis, keep an eye on every known venerability and update the fw systematically... it's a bureaucratic nightmare.
Let me get the word tinyest violin to play a sad song.
It's too easy to release any kind of software, which results bad software everywhere. Now at least there are some standards for it.

We can be ironic all we want, the fact is most of the European makers are small to medium size companies, the fact will be slower market growth and more compagnies reluctant to R&D.
You ready to accept the additional cost of certification and maintenance on a stupid thermostat that you probably will never connect to internet ?
You think a certification is a guarantee for a "good" software ?



 

Online SiliconWizard

  • Super Contributor
  • ***
  • Posts: 17795
  • Country: fr
Re: Scope of EU Cyber Resilience Act
« Reply #7 on: November 23, 2025, 09:37:51 pm »
Well, isn't that what has happened already as a whole in the EU? A lot of smaller companies shutting down and the large ones thriving? (Asking for a friend.)

Now, on the bright side, if that can limit the appeal to make IoT devices all over the place, that's a bonus in my book. There are just too many of these, often for no good reason. But, here again, I don't really think the fact that only the big ones will be able to afford it is a good thing either for consumers.

But yes, if that can make companies think twice before turning every little product into something connected to the Internet, that's not necessarily a bad thing from that perspective.
 
The following users thanked this post: hamdi.tn

Offline tszaboo

  • Super Contributor
  • ***
  • Posts: 9823
  • Country: nl
  • Current job: ATEX product design
Re: Scope of EU Cyber Resilience Act
« Reply #8 on: November 23, 2025, 09:38:37 pm »
What this will do really is, kill small IoT suppliers and developer, they have to add the cost of the infrastructure and HR needed to maintain the documentation required by CRA and RED DA, the infrastructure to collect the security related data for their devices for a minimum of 10 years, the cost of tools to automate documentation production and software analysis, keep an eye on every known venerability and update the fw systematically... it's a bureaucratic nightmare.
Let me get the word tinyest violin to play a sad song.
It's too easy to release any kind of software, which results bad software everywhere. Now at least there are some standards for it.

We can be ironic all we want, the fact is most of the European makers are small to medium size companies, the fact will be slower market growth and more compagnies reluctant to R&D.
You ready to accept the additional cost of certification and maintenance on a stupid thermostat that you probably will never connect to internet ?
You think a certification is a guarantee for a "good" software ?
Do you even understand it, where this is applicable?
 

Offline hamdi.tn

  • Frequent Contributor
  • **
  • Posts: 638
  • Country: tn
Re: Scope of EU Cyber Resilience Act
« Reply #9 on: November 23, 2025, 10:53:22 pm »
Do you even understand it, where this is applicable?

Yes I do. I work with couple of semi-conductor manufacturer on a daily basis and participated in events covering the subject and I sit on tons of documentation covering it.

Well, isn't that what has happened already as a whole in the EU? A lot of smaller companies shutting down and the large ones thriving? (Asking for a friend.)

Now, on the bright side, if that can limit the appeal to make IoT devices all over the place, that's a bonus in my book. There are just too many of these, often for no good reason. But, here again, I don't really think the fact that only the big ones will be able to afford it is a good thing either for consumers.

But yes, if that can make companies think twice before turning every little product into something connected to the Internet, that's not necessarily a bad thing from that perspective.

I can't agree more, yes to the EU point, and yes a lot of useless connected products popup every single day, it's extremely annoying to see a lot of companies just throwing money on useless devices and ideas.

However, consequence of my job, I know a lot of small compagnies (in France mainly) with a single role as supplier that orbit around big compagnies such in railway (sncf). So yes, there is a lot of noise in the market but there is also a lot of single, niche applications, some even with single customer.

An other perspective is when looking at history, Innovation is a result of trial and error, limiting the opportunity to create by regulation is limiting the opportunity to innovate. This will also limit competition possibilities and will shift the market in favor of couple of providers that will shape the market and force the prices.

This will not stop people from coming up with connected stuff, just it will be created and even certified elsewhere, for instance certification costs are lower in China, and the equivalent standard in the US is not mandatory (As far as I know), so companies will either produce, certify or even shift their market to outside of the EU

« Last Edit: November 23, 2025, 10:58:47 pm by hamdi.tn »
 

Offline KE5FX

  • Super Contributor
  • ***
  • Posts: 2638
  • Country: us
    • KE5FX.COM
Re: Scope of EU Cyber Resilience Act
« Reply #10 on: November 24, 2025, 12:24:17 am »
The problem with these regs is they don't scale with the size of the enterprise.  It doesn't matter whether you're a one-man shop or Microsoft, you have to jump through the same hoops.  Of course, Microsoft can afford to comply with any regulatory requirements imaginable, while their competition doesn't have that luxury.

The losers are, of course, consumers, and ultimately the EU economy as a whole since competitors can't afford to get off the ground.  But hey, at least everyone is "safe."
 
The following users thanked this post: hamdi.tn

Offline tszaboo

  • Super Contributor
  • ***
  • Posts: 9823
  • Country: nl
  • Current job: ATEX product design
Re: Scope of EU Cyber Resilience Act
« Reply #11 on: November 24, 2025, 08:51:08 am »
Do you even understand it, where this is applicable?

Yes I do. I work with couple of semi-conductor manufacturer on a daily basis and participated in events covering the subject and I sit on tons of documentation covering it.
Since it's covered under RED, Radio Equipment Directive, it's not applicable to a
on a stupid thermostat that you probably will never connect to internet ?
So I would suggest to double check the applicability. And what is even a stupid thermostat that you "probably" don't connect to the internet? Can you connect it? In that case it's not stupid. And the EU laws and regulations are applicable to products sold in the EU. If you don't like it, you can take your product elsewhere and sell it to people with lower standards.
 

Offline hamdi.tn

  • Frequent Contributor
  • **
  • Posts: 638
  • Country: tn
Re: Scope of EU Cyber Resilience Act
« Reply #12 on: November 24, 2025, 11:52:18 am »
"if you don't like it leave" said the guy who will hate to live in a dystopia :clap:

"people with lower standards." having a standard or a regulation does not give a higher status by itself  :palm: You will not consider countries that have a law to cut heads and hands based on the "secure society" argument, higher than those who doesn't.

 

Offline hamdi.tn

  • Frequent Contributor
  • **
  • Posts: 638
  • Country: tn
Re: Scope of EU Cyber Resilience Act
« Reply #13 on: November 24, 2025, 11:53:35 am »
The losers are, of course, consumers, and ultimately the EU economy as a whole since competitors can't afford to get off the ground.  But hey, at least everyone is "safe."

Exactly !
 

Offline temperance

  • Super Contributor
  • ***
  • Posts: 1609
  • Country: 00
Re: Scope of EU Cyber Resilience Act
« Reply #14 on: November 24, 2025, 12:56:36 pm »
Quote
Since it's covered under RED, Radio Equipment Directive, it's not applicable to a

That will no longer be the case soon.
 

Offline tszaboo

  • Super Contributor
  • ***
  • Posts: 9823
  • Country: nl
  • Current job: ATEX product design
Re: Scope of EU Cyber Resilience Act
« Reply #15 on: November 24, 2025, 01:07:55 pm »
"if you don't like it leave" said the guy who will hate to live in a dystopia :clap:

"people with lower standards." having a standard or a regulation does not give a higher status by itself  :palm: You will not consider countries that have a law to cut heads and hands based on the "secure society" argument, higher than those who doesn't.
I design stuff that is placed into explosive atmospheres.
The cyber resilience act doesn't have 1/100th of the documentation or certification requirement compared to the stuff I make.

All I hear is the typical whiling of a software guy who needs to write a single page documentation.
 

Offline hamdi.tn

  • Frequent Contributor
  • **
  • Posts: 638
  • Country: tn
Re: Scope of EU Cyber Resilience Act
« Reply #16 on: November 24, 2025, 02:29:21 pm »
I design stuff that is placed into explosive atmospheres.
The cyber resilience act doesn't have 1/100th of the documentation or certification requirement compared to the stuff I make.
All I hear is the typical whiling of a software guy who needs to write a single page documentation.

Let me get the word tiniest violin to play a sad song and feel your pain.

Are you for real mate, you comparing rules applied to explosive environments to generic consumer grade devices, you aware everything is made for a price, I don't think you make 100x documentation for free and you sale the same ATEX device for the same price as non-ATEX device.

By the way, I designed Gas control boards, got them certified, I have no issue with providing documentation. I have issue with regulation that threat the market stability, add cost to products, make them inaccessible for customers and then Brussels cry about a recession. If you never saw this before happening, check the news of the automotive industry.

And it will push small players to leave the market for big compagnies (will be bad for a guy who will hate to be under a corpocracy)  :-+

 

Offline madires

  • Super Contributor
  • ***
  • Posts: 9192
  • Country: de
  • A qualified hobbyist ;)
Re: Scope of EU Cyber Resilience Act
« Reply #17 on: November 24, 2025, 02:58:54 pm »
As a consumer I have three choices at the moment:
- inexpensive IoT/router/whatever with up to about two years updates
- expensive IoT/router/whatever with up to around 10 years updates
- something in between

Do the math and also consider e-waste/recycling.
 

Offline tszaboo

  • Super Contributor
  • ***
  • Posts: 9823
  • Country: nl
  • Current job: ATEX product design
Re: Scope of EU Cyber Resilience Act
« Reply #18 on: November 24, 2025, 03:20:03 pm »
I design stuff that is placed into explosive atmospheres.
The cyber resilience act doesn't have 1/100th of the documentation or certification requirement compared to the stuff I make.
All I hear is the typical whiling of a software guy who needs to write a single page documentation.

Let me get the word tiniest violin to play a sad song and feel your pain.

Are you for real mate, you comparing rules applied to explosive environments to generic consumer grade devices, you aware everything is made for a price, I don't think you make 100x documentation for free and you sale the same ATEX device for the same price as non-ATEX device.

By the way, I designed Gas control boards, got them certified, I have no issue with providing documentation. I have issue with regulation that threat the market stability, add cost to products, make them inaccessible for customers and then Brussels cry about a recession. If you never saw this before happening, check the news of the automotive industry.

And it will push small players to leave the market for big compagnies (will be bad for a guy who will hate to be under a corpocracy)  :-+
Products not complying with CRA can do a lot more damage than a single product not complying with ATEX.
You can have a foreign actor shut down all your "dumb thermostats" in your country, leading hundreds of people dead during a winter.
Or blow up your energy grid: https://www.reuters.com/sustainability/climate-energy/ghost-machine-rogue-communication-devices-found-chinese-inverters-2025-05-14

As I said, if you don't like it, that's fine, because nobody cares. Complain about the laws of other countries you don't live in.
 

Offline Matrix_Glitch

  • Contributor
  • !
  • Posts: 16
  • Country: si
Re: Scope of EU Cyber Resilience Act
« Reply #19 on: November 24, 2025, 03:26:46 pm »
Products not complying with CRA can do a lot more damage than a single product not complying with ATEX.
You can have a foreign actor shut down all your "dumb thermostats" in your country, leading hundreds of people dead during a winter.
Or blow up your energy grid: https://www.reuters.com/sustainability/climate-energy/ghost-machine-rogue-communication-devices-found-chinese-inverters-2025-05-14

As I said, if you don't like it, that's fine, because nobody cares. Complain about the laws of other countries you don't live in.

No need. VonDerCrazy took care of both issues.
No gas reserves for heating and industry.
Same with energy grid.
Greens are dismantling it.

What's your problem, again ? 🙄
 

Offline hamdi.tn

  • Frequent Contributor
  • **
  • Posts: 638
  • Country: tn
Re: Scope of EU Cyber Resilience Act
« Reply #20 on: November 24, 2025, 04:05:54 pm »
Well ... I posted my comment to add a point a view to the conversation, not to convince, least of all a guy that believe government write laws in his interest. You can keep babbling around all you wish, sure everybody is interested to hear your voice where you live. this discussion is over.
« Last Edit: November 24, 2025, 05:53:44 pm by hamdi.tn »
 

Offline eutectique

  • Frequent Contributor
  • **
  • Posts: 634
  • Country: be
Re: Scope of EU Cyber Resilience Act
« Reply #21 on: November 24, 2025, 05:17:57 pm »
look at a map you dump arrogant fuck that speak in the name of "everybody"

Welcome to my ignore list.
 

Offline hamdi.tn

  • Frequent Contributor
  • **
  • Posts: 638
  • Country: tn
Re: Scope of EU Cyber Resilience Act
« Reply #22 on: November 24, 2025, 05:52:52 pm »
look at a map you dump arrogant fuck that speak in the name of "everybody"

Welcome to my ignore list.

Fair enough, sorry for the outburst. Edited my comment. 
 

Offline tszaboo

  • Super Contributor
  • ***
  • Posts: 9823
  • Country: nl
  • Current job: ATEX product design
Re: Scope of EU Cyber Resilience Act
« Reply #23 on: November 24, 2025, 09:23:40 pm »
look at a map you dump arrogant fuck that speak in the name of "everybody"

Welcome to my ignore list.
Yeah, same here. Or maybe he doesn't know how to set up the country flag, couldn't care less.
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf

 

-->