

The New European Cybersecurity Regulation: Cyber Resilience Act
The Cyber Resilience Act (CRA) of the European Union represents a pivotal piece of legislation focused on the cybersecurity of digital products. It applies to a wide range of devices, including both hardware and software with digital elements, such as IoT devices and embedded systems. Compliance obligations include risk assessment, implementation of security features, and vulnerability management. Additionally, manufacturers of connected products must adhere to specific deadlines related to the reporting of vulnerabilities and security incidents. With enforcement set to begin in December 2027, companies still have time to adapt but must act quickly in the development phase. Raspberry Pi aims to assist its customers with compliance by providing products and resources that facilitate the transition to the new regulation, thereby reducing the workload for engineers and designers.
Critical Analysis
The Cyber Resilience Act emerges as a necessary measure to confront the rising concerns over the security of connected devices. However, the balance between user protection and pressures on manufacturers remains delicate. While companies like Raspberry Pi offer to assist with compliance, there is an inherent risk that small and medium-sized enterprises may find themselves overwhelmed by the new regulations. Effective implementation of such requirements necessitates deep understanding and adequate resources, which may not be sustainable for all manufacturers. It will be crucial to monitor how the market responds to these new responsibilities and the adaptation processes that follow.
Pros and Cons
| Pros | Cons |
|---|---|
| Enhanced security for devices | Increased compliance costs |
| Transparency towards customers | Potential hindrance for SMEs |
| Legal protection for manufacturers | Requirement for new expertise |
| Streamlined European market | High risk of non-compliance |
Sources
Author: Tom Westcott
URL: https://www.raspberrypi.com/news/raspberry-pi-and-the-eu-cyber-resilience-act/
Publication Date: 2023-10-05
Rights and Attribution
Images, logos, and photographs are the property of their respective owners. Used for commentary purposes.
← Back to blog