Ready for CRA?

First obligations of EU Cyber Resilience Act (CRA) begin today, with much more to come next year. We are as prepared as we can be. Are you ready? I doubt it.

CRA is a major step forward in cybersecurity. CRA is not yet another cybersecurity regulation. CRA sets up an entire framework for cybersecurity of digital products. It starts a new era. Even though CRA creates a lot of work for us, I fully support it. That work is necessary. In fact, something like CRA should be already in place long time ago.

However, there are major downsides. It is very obvious that EU agencies and standardization bodies were absolutely not ready for CRA. Horizontal standards are not finished, some crucial standards are not even drafted yet. Vertical standards are not ready either. E.g. IAM vertical standard does not exist at all.

MidPoint has to fully comply with CRA requirements by 11 Dec 2027. We have 12-month development cycle, which means I need to process CRA-mandated cybersecurity requirements now, design the controls, and submit detailed specification of cybersecurity improvements to our development team. Right now. How am I supposed to do that, without appropriate technical standards in place?

As usual: A great idea, which gets crippled by implementation problems. Another lost chance for major cybersecurity improvement across the entire industry.