Time to Read 1 min
The entry into force of the Cyber Resilience Act (CRA) means that almost no electronic product can be developed without taking cybersecurity into account, without a dam to the internet. Many things that previously only applied to critical infrastructures (NIS-2: Network and Information Systems Directive 2022/2555) now affect most electronic products.
What does this mean for you? We have compiled information here on various aspects of CRA and NIS-2:
Please feel free to contact Alois Cavelti if you have any further questions!
The fundamental difference is the scope: CRA applies to products with digital elements, while NIS-2 applies to organizations that operate critical infrastructure and their services. Therefore, CRA is more of a technical regulation, while NIS-2 is more of an organizational one.
Legal enforcement also differs: while CRA is directly applicable throughout the EU, NIS 2 has been/will be transposed into national law by all member states.
In principle, devices for markets regulated by NIS 2 can be developed in a similar or identical manner as for CRA. This is particularly true given the continuing lack of harmonized standards.
The CRA focuses on the security of the product itself in order to minimize the risk of cyberattacks. The GDPR (General Data Protection Regulation) focuses on the protection of personal data processed by these products.
A product secured by the CRA is a powerful technical lever for meeting the requirements of the GDPR.
ETSI EN 303 645 is a technical standard that is intended to translate the cybersecurity component of the RED (Radio Equipment Directive) and/or the CSA (Cybersecurity Act) into clear technical and procedural requirements. The same could also apply to the CRA.
However, since ETSI EN 303 645 is not harmonized with any of the regulations, compliance with the standard does not imply conformity.
The EU Commission can designate standards in the Official Journal as „harmonized” with certain regulations. If a product meets the requirements of the (harmonized) standard, the regulatory authority assumes that the corresponding legal requirements („essential requirements”) of the relevant regulation are also met; this is the presumption of conformity. Clear standards thus make CE marking considerably easier.

is Dipl. Ing./BSc ZFH in Informatik and develops software ranging from sensors to the cloud. His professional career is characterized by a deep curiosity for innovation and everything new in the digital world. To balance his everyday work with technology, he keeps fit and active by participating in a wide range of sports.

is Dipl. Elektroingenieur FH , co-founder, deputy managing director and software developer. He is a specialist for architectures and software in C, C++ and C#. He is committed to maintainable architecture, security and clean code. For this he likes to look beyond the "embedded" edge of his nose into other areas of software development. He is interested in overall systems of any kind and their interrelationships. Alois manages a 5'000 m2 biodiversity island and brings nature, horses and humans in harmony. He loves good (movie) stories and good food.
Projects? Ideas? Questions? Let's do a free initial workshop!
No Comments