Are we ready to go for CRA?

Are we ready to go for #CRA?



The Cyber Resilience Act (CRA) is a regulation proposed by the European Commission to improve cybersecurity for hardware and software products sold in the EU. 


1. Scope

  • All connected devices (#CPS: IoT, OT, Embedded devices etc.)


2. Key Security Requirements

  • Secure-by-Design Development
  • Vulnerability Management & Patching
  • Incident & Vulnerability Disclosure
  • Mandatory Compliance Assessments\
  • etc.


3. Timeline & Penalties

  • Enforced by 2025–2026
  • Penalties up to €15M or 2.5% of global annual turnover

***In the case of the Netherlands, the CRA will come into effect in 2025 and will force companies. A 24-month transition period will be in place.***

https://www.nldigitalgovernment.nl/news/european-council-approves-cyber-resilience-act-cra/


As a result we can expect that manufacturers and distributors of CPS meet cyber resilience principles lifecycle through the CRA. And security operators on sites can manage CRA requirements, such as ‘vulnerability/patches and incidents’ management, by leveraging OT Security tech solutions.


#CPS #OT #XIoT #IoT #IIoT #IoMT #CPSSecurity #OTSecurity #IoTSecurity #CPS보안 #OT보안 #IoT보안

Comments

Popular posts from this blog

Don't confuse DCS, PLC and SCADA in front of OT specialists

Top 20 Threat Scenarios & Playbooks for OT Security

Let's create our own ICS Labs in the VMs!