{"id":4817,"date":"2022-11-26T17:23:52","date_gmt":"2022-11-26T16:23:52","guid":{"rendered":"https:\/\/sanctuary.dev\/?p=4817"},"modified":"2022-12-12T17:24:33","modified_gmt":"2022-12-12T16:24:33","slug":"one-the-upcoming-eu-cyber-resilience-act","status":"publish","type":"post","link":"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/","title":{"rendered":"On the Upcoming EU Cyber Resilience Act"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"4817\" class=\"elementor elementor-4817\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-7fc26df nd-elementor-section-full elementor-section-height-default elementor-section-height-default\" data-id=\"7fc26df\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-cea95c0\" data-id=\"cea95c0\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-ac35c3b elementor-widget elementor-widget-text-editor\" data-id=\"ac35c3b\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p class=\"nd-font-size-intro\">In this blog post, we introduce the recently published draft of the EU Cyber Resilience Act (CRA) which aims to substantially increase the cybersecurity of products sold in the European Union. Moreover, we discuss why the CRA regulations are especially costly to implement when products rely on open-source software.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-1be72df nd-elementor-section-full elementor-section-height-default elementor-section-height-default\" data-id=\"1be72df\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-5015025\" data-id=\"5015025\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-bb4a398 elementor-widget elementor-widget-text-editor\" data-id=\"bb4a398\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>The draft of the <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/cyber-resilience-act\">Cyber Resilience Act (CRA)<\/a> presented by the European Commission is an important step towards strengthening the general cybersecurity of products sold in the EU. Especially for critical products, which are used e.g. in the industrial environment in the form of Industrial Automation &amp; Control Systems (IACS) or Industrial Internet of Things (IIoT) devices, a higher protection against cyberattacks is long overdue. Past cyberattacks, e.g. the WannaCry ransomware (2017) or the software supply chain attacks on software from SolarWind (2021) or Kaseya (2021), impressively demonstrated that cyberattacks can cause economic damage in the billions.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-7d465a8 nd-elementor-section-full elementor-section-height-default elementor-section-height-default\" data-id=\"7d465a8\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-77c2ca6\" data-id=\"77c2ca6\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-9ab52a6 elementor-widget elementor-widget-text-editor\" data-id=\"9ab52a6\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>In order to increase the cybersecurity of products, the CRA draft calls for a number of technical characteristics that regulated products must fulfill (<a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/cyber-resilience-act\">see Annex I<\/a>). In addition, the product manufacturer is required to take further steps during product development and subsequent product support, including conducting a cybersecurity risk assessment, performing due diligence when integrating third-party components, documenting relevant cybersecurity aspects, e.g., vulnerabilities that have become known, and implementing rules and procedures to disclose and address vulnerabilities (<a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/cyber-resilience-act\">see chapter 2, article 10<\/a>). Today, it is inevitable that the software running on those products is composed of in-house developments, purchased solutions from suppliers and open source software, e.g. in the form of software libraries, applications or operating systems. The CRA states very clearly that open source software itself is not covered by the regulation, in order to not hamper the publication of open source software (<a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/cyber-resilience-act\">see page 15, paragraph 10<\/a>). However, the CRA also states that the cybersecurity of open source software must be guaranteed by the product vendor when included into the product (<a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/cyber-resilience-act\">see page 39, paragraph 4<\/a>). Verifying all open source software components to prevent a cyberattacker from compromising the product will lead to a tremendous increase of the product development costs for the vendors.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-348190a nd-elementor-section-big elementor-section-height-default elementor-section-height-default\" data-id=\"348190a\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-a0cefe3\" data-id=\"a0cefe3\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-7bfcd2c nd-elementor-section-full elementor-section-height-default elementor-section-height-default\" data-id=\"7bfcd2c\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-ced0881\" data-id=\"ced0881\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-22f8e47 elementor-widget elementor-widget-nd-image\" data-id=\"22f8e47\" data-element_type=\"widget\" data-widget_type=\"nd-image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<div class=\"nd-image\">\n    \n            <figure>\n    \n        \n                <div class=\"d-flex flex-wrapper align-items-start\">\n                                            <img decoding=\"async\" style=\"\" src=\"https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/ossX.png\" class=\"full-image \"  srcset=\"https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/ossX.png 1311w, https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/ossX-720x320.png 720w, https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/ossX-1162x517.png 1162w, https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/ossX-18x8.png 18w, https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/ossX-480x213.png 480w\" sizes=\"(min-width: 768px) 100vw, 100vw\" alt=\"Open-Source Security Numbers\">\n                                    <\/div>\n            \n        \n        \n                <figcaption class=\"nd-image__caption\">\n                Usage of open source software according to Bitkom Open Source Monitor 2021\n            <\/figcaption>\n        <\/figure>\n    <\/div>\n\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-0e3b77c nd-elementor-section-full elementor-section-height-default elementor-section-height-default\" data-id=\"0e3b77c\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-d26ce53\" data-id=\"d26ce53\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-1d34f83 elementor-widget elementor-widget-text-editor\" data-id=\"1d34f83\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>According to the <a href=\"https:\/\/www.bitkom.org\/sites\/main\/files\/2021-12\/211207-bitkom-studie-openmonitor-2021.pdf\">Bitkom Open Source Monitor<\/a> from 2021, 71% of the questioned companies stated that they use open source software, whereby 41% of those said that they also integrate open source software into their own products. The reasons why open source software is used are manifold, but the most important aspect is cost saving. From a research point-of-view. there is no clear evidence that open source software is in general more or less secure than software developed in-house. The cybersecurity of open source software depends on multiple factors like the financial situation of the open source project, or the experience and number of its developers. In a <a href=\"https:\/\/publications.teamusec.de\/2022-oakland-sec-oss\/pdf\/committed-to-trust-preprint.pdf\">study<\/a> performed by the CISPA research center in 2022, 30% of the questioned open source projects did not define a security policy and 18% did not define a person responsible for cybersecurity topics. This shows that a cybersecurity analysis of open source software is to be recommended. Unfortunately, the Bitkom Open Source Monitor revealed that 23% of the questioned companies do not check the security of the open source software they use.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-fb6edb5 nd-elementor-section-big elementor-section-height-default elementor-section-height-default\" data-id=\"fb6edb5\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-510e844\" data-id=\"510e844\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-18dc0c2 nd-elementor-section-full elementor-section-height-default elementor-section-height-default\" data-id=\"18dc0c2\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-9b92223\" data-id=\"9b92223\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-0a719de elementor-widget elementor-widget-nd-image\" data-id=\"0a719de\" data-element_type=\"widget\" data-widget_type=\"nd-image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<div class=\"nd-image\">\n    \n            <figure>\n    \n        \n                <div class=\"d-flex flex-wrapper align-items-start\">\n                                            <img decoding=\"async\" style=\"\" src=\"https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/oss_sec.png\" class=\"full-image \"  srcset=\"https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/oss_sec.png 1867w, https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/oss_sec-720x139.png 720w, https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/oss_sec-1620x313.png 1620w, https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/oss_sec-1162x225.png 1162w, https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/oss_sec-1536x297.png 1536w, https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/oss_sec-18x3.png 18w, https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/oss_sec-480x93.png 480w\" sizes=\"(min-width: 768px) 100vw, 100vw\" alt=\"Open-Source Security Numbers\">\n                                    <\/div>\n            \n        \n        \n                <figcaption class=\"nd-image__caption\">\n                Statistics on the security of open source software\n            <\/figcaption>\n        <\/figure>\n    <\/div>\n\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-9756455 nd-elementor-section-full elementor-section-height-default elementor-section-height-default\" data-id=\"9756455\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-815a3b5\" data-id=\"815a3b5\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f4d2240 elementor-widget elementor-widget-text-editor\" data-id=\"f4d2240\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>The great danger of insecure open source components is that a cyberattacker can exploit vulnerabilities in the open source software to infiltrate the system and in the end compromise the complete product. In the case of open source software, handling these threats with the help of compliance processes, in which the responsibility for the correctness and maintenance of the software is handed over to the supplier, is of course not possible since the authors of the open source software cannot be held liable. Thus, very time and cost intensive cybersecurity analyses of the source code of open source software must be performed by the vendor in order to not endanger the security of the product.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-bb420c0 nd-elementor-section-full elementor-section-height-default elementor-section-height-default\" data-id=\"bb420c0\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-12393fc\" data-id=\"12393fc\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-2fea2e1 elementor-widget elementor-widget-text-editor\" data-id=\"2fea2e1\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>The SANCTUARY Zero-Trust Platform tackles exactly the described challenge, where open source software is combined with third-party and in-house software on critical embedded devices. With its strong isolation features, the Zero-Trust Platform encapsulates software components and separates them from each other. As a result, a vulnerability in one software component which gets exploited by an cyberattacker will not negatively influence the security of the other software components. With regard to the EU Cyber Resilience Act (CRA), the SANCTUARY Zero-Trust Platform allows vendors to build products that fulfill the technical requirements of the CRA and at the same time to keep the development time of the products low since a less stringent security analysis is required to keep the entire product secure.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>In this blog post, we introduce the recently published draft of the EU Cyber Resilience Act (CRA) which aims to substantially increase the cybersecurity of products sold in the European Union. Moreover, we discuss why the CRA regulations are especially costly to implement when products rely on open-source software. <\/p>\n","protected":false},"author":14,"featured_media":4819,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[32],"tags":[48,47,50,49],"class_list":["post-4817","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-cyber-resilience-act","tag-eu","tag-lawmaking","tag-regulations"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>On the Upcoming EU Cyber Resilience Act - SANCTUARY<\/title>\n<meta name=\"description\" content=\"In this blog post, we introduce the recently published draft of the EU Cyber Resilience Act (CRA) which aims to substantially increase the cybersecurity of products sold in the European Union. Moreover, we discuss why the CRA regulations are especially costly to implement when products rely on open-source software.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"On the Upcoming EU Cyber Resilience Act - SANCTUARY\" \/>\n<meta property=\"og:description\" content=\"In this blog post, we introduce the recently published draft of the EU Cyber Resilience Act (CRA) which aims to substantially increase the cybersecurity of products sold in the European Union. Moreover, we discuss why the CRA regulations are especially costly to implement when products rely on open-source software.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/\" \/>\n<meta property=\"og:site_name\" content=\"SANCTUARY\" \/>\n<meta property=\"article:published_time\" content=\"2022-11-26T16:23:52+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-12-12T16:24:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/cyber-resilience-act.png\" \/>\n\t<meta property=\"og:image:width\" content=\"3782\" \/>\n\t<meta property=\"og:image:height\" content=\"2128\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Emmanuel Stapf\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@sanctuary_dev\" \/>\n<meta name=\"twitter:site\" content=\"@sanctuary_dev\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/\"},\"author\":{\"name\":\"Emmanuel Stapf\",\"@id\":\"https:\/\/sanctuary.dev\/en\/#\/schema\/person\/4d45e6474ecd26ee1b20ff8a6dc48071\"},\"headline\":\"On the Upcoming EU Cyber Resilience Act\",\"datePublished\":\"2022-11-26T16:23:52+00:00\",\"dateModified\":\"2022-12-12T16:24:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/\"},\"wordCount\":782,\"publisher\":{\"@id\":\"https:\/\/sanctuary.dev\/en\/#organization\"},\"image\":{\"@id\":\"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/cyber-resilience-act.png\",\"keywords\":[\"Cyber Resilience Act\",\"EU\",\"Lawmaking\",\"Regulations\"],\"articleSection\":[\"News\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/\",\"url\":\"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/\",\"name\":\"On the Upcoming EU Cyber Resilience Act - SANCTUARY\",\"isPartOf\":{\"@id\":\"https:\/\/sanctuary.dev\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/cyber-resilience-act.png\",\"datePublished\":\"2022-11-26T16:23:52+00:00\",\"dateModified\":\"2022-12-12T16:24:33+00:00\",\"description\":\"In this blog post, we introduce the recently published draft of the EU Cyber Resilience Act (CRA) which aims to substantially increase the cybersecurity of products sold in the European Union. Moreover, we discuss why the CRA regulations are especially costly to implement when products rely on open-source software.\",\"breadcrumb\":{\"@id\":\"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/#primaryimage\",\"url\":\"https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/cyber-resilience-act.png\",\"contentUrl\":\"https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/cyber-resilience-act.png\",\"width\":3782,\"height\":2128,\"caption\":\"Banner EU Cyber Resilience Act\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/sanctuary.dev\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"On the Upcoming EU Cyber Resilience Act\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/sanctuary.dev\/en\/#website\",\"url\":\"https:\/\/sanctuary.dev\/en\/\",\"name\":\"SANCTUARY\",\"description\":\"The Embedded Security Experts\",\"publisher\":{\"@id\":\"https:\/\/sanctuary.dev\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/sanctuary.dev\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/sanctuary.dev\/en\/#organization\",\"name\":\"SANCTUARY\",\"url\":\"https:\/\/sanctuary.dev\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/sanctuary.dev\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/sanctuary.dev\/app\/uploads\/2022\/07\/sanctuary_linkedin_logo_v4.png\",\"contentUrl\":\"https:\/\/sanctuary.dev\/app\/uploads\/2022\/07\/sanctuary_linkedin_logo_v4.png\",\"width\":1841,\"height\":1841,\"caption\":\"SANCTUARY\"},\"image\":{\"@id\":\"https:\/\/sanctuary.dev\/en\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/x.com\/sanctuary_dev\",\"https:\/\/www.linkedin.com\/company\/sanctuary-dev\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/sanctuary.dev\/en\/#\/schema\/person\/4d45e6474ecd26ee1b20ff8a6dc48071\",\"name\":\"Emmanuel Stapf\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/sanctuary.dev\/en\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/5bf1073e869e3ed5120ffad94dcb6509dbe6c006658602d96a2758de4e2354ff?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/5bf1073e869e3ed5120ffad94dcb6509dbe6c006658602d96a2758de4e2354ff?s=96&d=mm&r=g\",\"caption\":\"Emmanuel Stapf\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"On the Upcoming EU Cyber Resilience Act - SANCTUARY","description":"In this blog post, we introduce the recently published draft of the EU Cyber Resilience Act (CRA) which aims to substantially increase the cybersecurity of products sold in the European Union. Moreover, we discuss why the CRA regulations are especially costly to implement when products rely on open-source software.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/","og_locale":"en_US","og_type":"article","og_title":"On the Upcoming EU Cyber Resilience Act - SANCTUARY","og_description":"In this blog post, we introduce the recently published draft of the EU Cyber Resilience Act (CRA) which aims to substantially increase the cybersecurity of products sold in the European Union. Moreover, we discuss why the CRA regulations are especially costly to implement when products rely on open-source software.","og_url":"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/","og_site_name":"SANCTUARY","article_published_time":"2022-11-26T16:23:52+00:00","article_modified_time":"2022-12-12T16:24:33+00:00","og_image":[{"width":3782,"height":2128,"url":"https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/cyber-resilience-act.png","type":"image\/png"}],"author":"Emmanuel Stapf","twitter_card":"summary_large_image","twitter_creator":"@sanctuary_dev","twitter_site":"@sanctuary_dev","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/#article","isPartOf":{"@id":"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/"},"author":{"name":"Emmanuel Stapf","@id":"https:\/\/sanctuary.dev\/en\/#\/schema\/person\/4d45e6474ecd26ee1b20ff8a6dc48071"},"headline":"On the Upcoming EU Cyber Resilience Act","datePublished":"2022-11-26T16:23:52+00:00","dateModified":"2022-12-12T16:24:33+00:00","mainEntityOfPage":{"@id":"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/"},"wordCount":782,"publisher":{"@id":"https:\/\/sanctuary.dev\/en\/#organization"},"image":{"@id":"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/#primaryimage"},"thumbnailUrl":"https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/cyber-resilience-act.png","keywords":["Cyber Resilience Act","EU","Lawmaking","Regulations"],"articleSection":["News"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/","url":"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/","name":"On the Upcoming EU Cyber Resilience Act - SANCTUARY","isPartOf":{"@id":"https:\/\/sanctuary.dev\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/#primaryimage"},"image":{"@id":"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/#primaryimage"},"thumbnailUrl":"https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/cyber-resilience-act.png","datePublished":"2022-11-26T16:23:52+00:00","dateModified":"2022-12-12T16:24:33+00:00","description":"In this blog post, we introduce the recently published draft of the EU Cyber Resilience Act (CRA) which aims to substantially increase the cybersecurity of products sold in the European Union. Moreover, we discuss why the CRA regulations are especially costly to implement when products rely on open-source software.","breadcrumb":{"@id":"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/#primaryimage","url":"https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/cyber-resilience-act.png","contentUrl":"https:\/\/sanctuary.dev\/app\/uploads\/2022\/12\/cyber-resilience-act.png","width":3782,"height":2128,"caption":"Banner EU Cyber Resilience Act"},{"@type":"BreadcrumbList","@id":"https:\/\/sanctuary.dev\/en\/blog\/one-the-upcoming-eu-cyber-resilience-act\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/sanctuary.dev\/en\/"},{"@type":"ListItem","position":2,"name":"On the Upcoming EU Cyber Resilience Act"}]},{"@type":"WebSite","@id":"https:\/\/sanctuary.dev\/en\/#website","url":"https:\/\/sanctuary.dev\/en\/","name":"SANCTUARY","description":"The Embedded Security Experts","publisher":{"@id":"https:\/\/sanctuary.dev\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sanctuary.dev\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/sanctuary.dev\/en\/#organization","name":"SANCTUARY","url":"https:\/\/sanctuary.dev\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sanctuary.dev\/en\/#\/schema\/logo\/image\/","url":"https:\/\/sanctuary.dev\/app\/uploads\/2022\/07\/sanctuary_linkedin_logo_v4.png","contentUrl":"https:\/\/sanctuary.dev\/app\/uploads\/2022\/07\/sanctuary_linkedin_logo_v4.png","width":1841,"height":1841,"caption":"SANCTUARY"},"image":{"@id":"https:\/\/sanctuary.dev\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/sanctuary_dev","https:\/\/www.linkedin.com\/company\/sanctuary-dev\/"]},{"@type":"Person","@id":"https:\/\/sanctuary.dev\/en\/#\/schema\/person\/4d45e6474ecd26ee1b20ff8a6dc48071","name":"Emmanuel Stapf","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sanctuary.dev\/en\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/5bf1073e869e3ed5120ffad94dcb6509dbe6c006658602d96a2758de4e2354ff?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/5bf1073e869e3ed5120ffad94dcb6509dbe6c006658602d96a2758de4e2354ff?s=96&d=mm&r=g","caption":"Emmanuel Stapf"}}]}},"_links":{"self":[{"href":"https:\/\/sanctuary.dev\/en\/wp-json\/wp\/v2\/posts\/4817","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sanctuary.dev\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sanctuary.dev\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sanctuary.dev\/en\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/sanctuary.dev\/en\/wp-json\/wp\/v2\/comments?post=4817"}],"version-history":[{"count":17,"href":"https:\/\/sanctuary.dev\/en\/wp-json\/wp\/v2\/posts\/4817\/revisions"}],"predecessor-version":[{"id":4857,"href":"https:\/\/sanctuary.dev\/en\/wp-json\/wp\/v2\/posts\/4817\/revisions\/4857"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sanctuary.dev\/en\/wp-json\/wp\/v2\/media\/4819"}],"wp:attachment":[{"href":"https:\/\/sanctuary.dev\/en\/wp-json\/wp\/v2\/media?parent=4817"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sanctuary.dev\/en\/wp-json\/wp\/v2\/categories?post=4817"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sanctuary.dev\/en\/wp-json\/wp\/v2\/tags?post=4817"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}