← /episodes
[ S01E05 ]EN2026-06-1118:32

S01E05 - Secure-by-design or off the market: the Cyber Resilience Act explained

S01E05 - Secure-by-design or off the market: the Cyber Resilience Act explained
▶ play episode
Download ↓

The Cyber Resilience Act — Regulation EU 2024/2847 — entered into force on December 10, 2024, and rewrites the rules for anyone placing software or hardware on the EU market. From smart thermostats to industrial firewalls: all products with digital elements must now meet mandatory cybersecurity requirements. Manufacturers who cannot demonstrate compliance will no longer be permitted to sell in Europe. Maximum penalties: €15 million or 2.5% of global annual turnover. The regulation applies to non-EU companies too — if your product reaches the European market, the CRA applies.

Michael and Nadine break down the four risk categories — from the default category (approximately 90% of all products, self-assessment permitted) to Important Class I and II (identity management systems, firewalls, intrusion detection — mandatory third-party or Notified Body assessment) and Critical (Annex IV). They go deep on the core Annex I obligations: secure-by-design and secure-by-default, vulnerability management across the full product lifecycle, mandatory SBOM documentation, a minimum 5-year security update period, and reporting deadlines of 24 hours (early warning) and 72 hours (full notification) via ENISA's CRA Single Reporting Platform. Two CRA obligations apply before the final enforcement date of December 11, 2027: from June 11, 2026, conformity assessment bodies must be notified; from September 11, 2026, vulnerability and incident reporting is mandatory.

The core insight of this episode: the CRA does not ask for a snapshot — it demands continuous, demonstrable proof of security across the entire product lifecycle. Attesto delivers that evidence layer: tamper-evident logging for all Annex I obligations, and the Proof of Evolution system to document the measurable progression of vulnerability management and security updates over time. The Nova/IVC cryptographic layer is already running live in production.