The EU Cyber Resilience Act (CRA) is now partially in effect as of July 2026, with full application coming in December 2027. Manufacturers of connected digital products (IoT devices, EV chargers, etc.) bear ultimate responsibility for CRA compliance. When working with a software development partner, responsibilities should be divided based on three principles: expertise alignment, operational feasibility and cost, and designing for independence over time. A practical responsibility table covers documentation, product development, identification, support, and vulnerability handling. Concrete practices from critical open source projects (sudo-rs, e-KS) illustrate how to meet CRA requirements: threat modelling, careful dependency selection with tools like Dependabot, coordinated vulnerability disclosure, and backporting security fixes to older versions.

11m read timeFrom tweedegolf.nl
Post cover image
Table of contents
The CRA in a nutshellWhat we think of the CRAThree guiding principlesTypical divisionMeeting the CRA requirements in practiceConclusion
978 Impressions