CRA full compliance required 453 days left What it means for you
THZ Networks Under attack? SOS — incident response, any hour of any day

ARTICLES

The CRA turns a product into a support commitment

Manufacturers read the Cyber Resilience Act as a certification hurdle. It is closer to a warranty — one that runs for years after the sale.

The duty does not end at the loading bay

The CRA requires products with digital elements to be supplied without known exploitable vulnerabilities, and then to be supported: vulnerabilities handled, security updates provided, and reporting obligations met for the support period you declare.

That is a commercial decision disguised as a technical one. Declare five years and you have staffed a five-year obligation for every unit you have sold, including the ones sitting in a distributor's warehouse.

You need a way to be told

A vulnerability handling process implies somebody can reach you. A published contact point and a coordinated disclosure policy are the cheapest part of the whole regulation and the most visible sign that the rest exists — which is why a researcher checks for one before deciding whether reporting to you is worth their afternoon.

We publish ours at /.well-known/security.txt for exactly that reason.

The boring findings are the ones that bite

In practice the things that fail a product review are not exotic. Shared or default credentials across a production run, debug and service interfaces left reachable, update mechanisms with no signature check, and no inventory of what third-party code is inside the firmware.

All four are cheaper to fix at design time than at recall time, and all four are visible in a single afternoon of testing.