Author:
Peter Schoo
Affiliation:
Independent Researcher, 82194 Gröbenzell, Germany
Keyword(s):
Cyber Resilience Act, CRA, Product Security, Security Engineering, Harmonised European Standards, Product Certification.
Abstract:
This short-paper analyses the forthcoming European Cybersecurity Legislation, focusing on the Cyber Resilience Act (CRA), with an examination of the challenges in defining the CRA addressing product security requirements, life-cycle and supply chain protection, and product criticality classification, that points to certification of product security. Stakeholders, including EU institutions, industry players and Open Source Software (OSS) community, play pivotal roles. The discussion provides a concise but complete overview of the regulatory content and context, the obligations and recommendations for action for companies and practical recommendations for courses at universities, as they arise from the CRA.