2026-03-06 12:51 UTC
CRA evaluation downgrade is not an attack, but a way to evade the more strict process reserved for important and critical products. Just make sure you product has more core functions than the one that puts you in to the category.
For example: NMS + SIEM + PKI, and you have a default product in your hands (Draft guidance on the application of CRA, section 6.1, Example 50). More attack surface and larger SPOF saves you money in the assessment complexity.
https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/16959-Draft-Commission-guidance-on-the-Cyber-Resilience-Act_en
Replies (0)
No replies.