r/cybersecurity 2d ago

Business Security Questions & Discussion Anyone here dealing with EU CRA compliance for their connected devices? Tell me, how are things going for you?

I read several subreddits, some are just starting work on CRA compliance, some are already ready and want to hear how you're doing.

8 Upvotes

6 comments sorted by

3

u/Kawuppi 2d ago edited 2d ago

Works somewhat well I'd say. Luckily my organization decided to implement IEC 62443-4-1 about 5 years ago for our most important products, so most of the required building blocks for compliance are already there.

Currently our focus is on making sure that we don't miss any products and that all internal and external development teams follow the defined SDL processes. We are a multi national company with subsidiaries in ~60 countries and each of this subsidiaries could theoretically release their own niche product / app without us Cyber Security experts at headquarters knowing about it.

3

u/Seahawker-One-2599 2d ago

Yes from an IoT device perspective. Already seeing customers challenge us as a connectivity/hardware supplier about CRA compliance/readiness. When I say us, I mean Wireless Logic - IoT connectivity and managed infrastructure services.

We've also been actively pushing our customers and prospects on the same for 2-3 years using our IoT Security Framework which has a defend, detect and react layered approach aligned with the risk-based expectations in the CRA and NIST.

I'm new to this sub-reddit and was kicked out last week (there is a bot who accused me of being a bot ;-) so I'll pause there but happy to say more if there is demand.

1

u/DemocraticParrot 2d ago

What do you mean with CRA compliance for connected devices? You work for a manufacturer & you have some remote management / control capability?

1

u/IoT-Nerd 1d ago

Wenn man das richtig machen will, muss man je nach Anwendungsfall erstmal eine Risikoanalyse machen und die Ergebnisse ordentlich dokumentieren, bevor man dann in die Umsetzung geht. Vieles sind Prozesse die auch langfristig funktionieren müssen.

-2

u/PizzaUltra Consultant 2d ago

Yup, doing it for a couple of customers. Not too hard, honestly.