{"id":53017,"date":"2026-08-26T15:20:20","date_gmt":"2026-08-26T19:20:20","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=53017"},"modified":"2026-08-26T16:04:25","modified_gmt":"2026-08-26T20:04:25","slug":"cyber-resilience-act","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2026\/08\/26\/cyber-resilience-act\/","title":{"rendered":"Cyber Resilience Act"},"content":{"rendered":"<p><a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cyber-resilience-act\">European Commission<\/a>:<\/p>\n<blockquote cite=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cyber-resilience-act\">\n<p>From baby-monitors to smart watches, from apps to computer programs, connectable hardware and software are omnipresent in our daily lives. Less apparent to many users is the security risk such products may present.<\/p>\n<p>The <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/cyber-resilience-act\">Cyber Resilience Act (CRA)<\/a> aims to safeguard consumers and businesses buying software or hardware products with digital elements. The CRA addresses the inadequate level of cybersecurity in many products, and the lack of timely security updates. It also tackles the challenges consumers and businesses currently face when trying to determining which products are cybersecure and in setting them up securely, making it easier to identify hardware and software with the proper cybersecurity features.<\/p>\n<p>The CRA introduces mandatory cybersecurity requirements for manufacturers, covering the planning, design, development and maintenance of such products. These obligations must be met at every stage of the value chain. The CRA also requires manufacturers to handle vulnerabilities during the lifecycle of their products. Some products of particular relevance for cybersecurity may need to undergo a third-party assessment by a notified body before they are sold on the EU market.<\/p>\n<\/blockquote>\n\n<p>Via <a href=\"https:\/\/mastodon.social\/@betamagic\/117162696672794548\">Ron Elemans<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.social\/@betamagic\/117162696672794548\">\n<p>[&#8230;] the extremely heavy future requirements that are due on December 11, 2027.<\/p>\n<p>For example, free security updates must be provided for at least five years without changes regarding the operating system requirements&mdash;a period that resets every time someone purchases an app of a particular version.<\/p><\/blockquote>\n\n<p>Here&rsquo;s the <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A32024R2847\">text of it<\/a>, which <a href=\"https:\/\/en.wikipedia.org\/wiki\/Cyber_Resilience_Act\">was approved in 2024<\/a>.<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2026\/08\/18\/new-eu-app-store-terms-to-comply-with-dma\/\">New EU App Store Terms to Comply With DMA<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2025\/11\/20\/europe-scaling-back-gdpr-and-ai-laws\/\">Europe Scaling Back GDPR and AI Laws<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>European Commission: From baby-monitors to smart watches, from apps to computer programs, connectable hardware and software are omnipresent in our daily lives. Less apparent to many users is the security risk such products may present. The Cyber Resilience Act (CRA) aims to safeguard consumers and businesses buying software or hardware products with digital elements. The [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2026-08-26T19:20:25Z","apple_news_api_id":"99ee1e42-352c-4f6b-9dba-e97ab53ed4f8","apple_news_api_modified_at":"2026-08-26T19:20:25Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/Ame4eQjUsT2uduul6tT7U-A","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[91,101,1927,31,209,30,48],"class_list":["post-53017","post","type-post","status-publish","format-standard","hentry","category-technology","tag-appstore","tag-business","tag-european-union","tag-ios","tag-legal","tag-mac","tag-security"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/53017","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=53017"}],"version-history":[{"count":1,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/53017\/revisions"}],"predecessor-version":[{"id":53018,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/53017\/revisions\/53018"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=53017"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=53017"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=53017"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}