Cyber Resilience Act
From baby-monitors to smart watches, from apps to computer programs, connectable hardware and software are omnipresent in our daily lives. Less apparent to many users is the security risk such products may present.
The Cyber Resilience Act (CRA) aims to safeguard consumers and businesses buying software or hardware products with digital elements. The CRA addresses the inadequate level of cybersecurity in many products, and the lack of timely security updates. It also tackles the challenges consumers and businesses currently face when trying to determining which products are cybersecure and in setting them up securely, making it easier to identify hardware and software with the proper cybersecurity features.
The CRA introduces mandatory cybersecurity requirements for manufacturers, covering the planning, design, development and maintenance of such products. These obligations must be met at every stage of the value chain. The CRA also requires manufacturers to handle vulnerabilities during the lifecycle of their products. Some products of particular relevance for cybersecurity may need to undergo a third-party assessment by a notified body before they are sold on the EU market.
Via Ron Elemans:
[…] the extremely heavy future requirements that are due on December 11, 2027.
For example, free security updates must be provided for at least five years without changes regarding the operating system requirements—a period that resets every time someone purchases an app of a particular version.
Here’s the text of it, which was approved in 2024.
Previously:
3 Comments RSS · Twitter · Mastodon
> free security updates must be provided for at least five years without changes regarding the operating system requirements
Is this even possible with current App Store rules? Once you update the minimum supported OS version of your app (which you might be forced to by newer Xcode versions, which Apple requires for submission, no longer supporting old OS releases), you can no longer provide updates for your older app versions on the App Store.
@Frederik probably not, and as written this law seems overly prescriptive.
Though like many EU laws lately, it was likely written specifically with Apple in mind, intending to force policy changes.
@Frederik,
I don't know. I haven't read through the 84-page FAQ yet.
But apparently, the reporting requirements go into effect in two weeks. We have over a year for functional requirements.
Clearly, the EU wants to take Apple down a peg or two. But they absolutely want to destroy small businesses, especially those that aren't in the EU.