# cyber resilience act

The Cyber Resilience Act (CRA) is an EU regulatory framework establishing cybersecurity requirements for hardware and software products with digital elements placed on the Union market.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Announcing the Sovereign Artifacts beta

DevFeed: [Announcing the Sovereign Artifacts beta](<https://devfeed.tech/articles/announcing-the-sovereign-artifacts-beta-26773.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-the-sovereign-artifacts-beta>)

Published: 2026-09-15T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Software](<https://devfeed.tech/topics/software.md>), [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [container](<https://devfeed.tech/tags/container.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [eu](<https://devfeed.tech/tags/eu.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [network](<https://devfeed.tech/tags/network.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [performance](<https://devfeed.tech/tags/performance.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Chainguard has launched Sovereign Artifacts in beta, providing EU-local storage and delivery for secure container and library artifact bytes. Phase 1 stores artifacts in the EU, while authentication and build pipelines remain hosted in the United States. The service is intended to support sovereignty and data-residency requirements and reduce artifact pull times for European customers.

### Source excerpt

Chainguard launches Sovereign Artifacts in beta, giving global organizations an EU-local option for secure container and library artifacts.

## How OSPOs Are Preparing Organizations for the EU Cyber Resilience Act

DevFeed: [How OSPOs Are Preparing Organizations for the EU Cyber Resilience Act](<https://devfeed.tech/articles/how-ospos-are-preparing-organizations-for-the-eu-cyber-resilience-act-14497.md>)

Original publisher: [Read original article](<https://www.linuxfoundation.org/blog/how-ospos-are-preparing-organizations-for-the-eu-cyber-resilience-act>)

Author: andrewb@proximabiz.com (The Linux Foundation)

Published: 2026-09-09T19:11:24Z

Content type: article

Language: en

Sources: [Linux Foundation - Blog](<https://devfeed.tech/sources/linux-foundation-blog.md>)

Topics: [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [eu](<https://devfeed.tech/tags/eu.md>), [linux-foundation](<https://devfeed.tech/tags/linux-foundation.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This Linux Foundation post explains how Open Source Program Offices can help organizations prepare for the EU Cyber Resilience Act, including identifying affected products and dependencies, coordinating legal, security, engineering and procurement teams, and responding to vulnerability and incident reporting obligations.

### Source excerpt

For organizations offering products with digital elements in the EU, the next major Cyber Resilience Act (CRA) deadline arrives on 11 September 2026. From that date, organizations covered by the reporting obligations must be ready to assess actively exploited vulnerabilities and severe security incidents, coordinate an internal response and submit notifications within the required timelines.

## EU Cyber Resilience Act: Vulnerability Reporting Obligations

DevFeed: [EU Cyber Resilience Act: Vulnerability Reporting Obligations](<https://devfeed.tech/articles/eu-cyber-resilience-act-vulnerability-reporting-obligations-13794.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/2026/09/esp32-cra-obligations-and-deadlines/>)

Author: John Lee

Published: 2026-09-09T00:00:00Z

Content type: article

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Espressif](<https://devfeed.tech/topics/espressif.md>), [ESP32](<https://devfeed.tech/topics/esp32.md>), [ESP-IDF](<https://devfeed.tech/topics/esp-idf.md>), [Security](<https://devfeed.tech/topics/security.md>), [EN 18031](<https://devfeed.tech/topics/en-18031.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [en-18031](<https://devfeed.tech/tags/en-18031.md>), [esp-idf](<https://devfeed.tech/tags/esp-idf.md>), [esp32](<https://devfeed.tech/tags/esp32.md>), [espressif](<https://devfeed.tech/tags/espressif.md>), [eu](<https://devfeed.tech/tags/eu.md>), [iot](<https://devfeed.tech/tags/iot.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This article explains that the Cyber Resilience Act's vulnerability-reporting obligations begin on 11 September 2026 for connected products sold in the EU, including products already on the market. It outlines Article 14 duties, reporting recipients and the role of Espressif's platform layer for products built on ESP32.

### Source excerpt

The CRA's vulnerability reporting obligations start on 11 September 2026 and apply to products already on the market, including ones sold years ago. What Article 14 requires, which duties run to whom, how reporting works through the ENISA Single Reporting Platform, and where the Espressif platform layer fits.

## How Teleport Operationalizes the EU Cyber Resilience Act's Secure-by-Design Mandate

DevFeed: [How Teleport Operationalizes the EU Cyber Resilience Act's Secure-by-Design Mandate](<https://devfeed.tech/articles/how-teleport-operationalizes-the-eu-cyber-resilience-act-s-secure-by-design-mandate-29639.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/eu-cra-secure-by-design/>)

Author: info@goteleport.com (Maximilian Heck, Waldemar Kindler)

Published: 2026-07-16T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [audit trail](<https://devfeed.tech/topics/audit-trail.md>), [Monitoring & Alerting](<https://devfeed.tech/topics/monitoring-alerting.md>)

Tags: [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [cra-requirements](<https://devfeed.tech/tags/cra-requirements.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [eu](<https://devfeed.tech/tags/eu.md>), [monitoring-alerting](<https://devfeed.tech/tags/monitoring-alerting.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article explains how Teleport maps its infrastructure identity, access, policy, logging, monitoring, and audit controls to ENISA's Secure by Design and Default Playbook and the EU Cyber Resilience Act. It highlights cryptographic identity, least privilege, secure communication, supply-chain controls, and default protection of device identities and secrets.

### Source excerpt

See how Teleport features map to ENISA's Secure-by-Design specification for CRA.

## CTRL-OS 26.05 Released!

DevFeed: [CTRL-OS 26.05 Released!](<https://devfeed.tech/articles/ctrl-os-26-05-released-31346.md>)

Original publisher: [Read original article](<https://discourse.nixos.org/t/ctrl-os-26-05-released/78843>)

Author: blitz

Published: 2026-07-10T12:35:43Z

Content type: release

Language: en

Sources: [Announcements - NixOS Discourse](<https://devfeed.tech/sources/announcements-nixos-discourse.md>)

Topics: [Nix](<https://devfeed.tech/topics/nix.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [maintenance](<https://devfeed.tech/topics/maintenance.md>), [Security](<https://devfeed.tech/topics/security.md>), [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>)

Tags: [announcements](<https://devfeed.tech/tags/announcements.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [linux](<https://devfeed.tech/tags/linux.md>), [maintenance](<https://devfeed.tech/tags/maintenance.md>), [release](<https://devfeed.tech/tags/release.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

CTRL-OS 26.05, a downstream distribution of NixOS, has been released. The release provides a five-year lifecycle model, beginning with co-maintenance while NixOS has community support and moving to stability maintenance afterward. CTRL-OS monitors and backports security fixes for a core package set, with commercial subscriptions supporting SLAs and custom package sets. The project also describes its role in helping embedded Linux products address long-term vulnerability patching and EU Cyber Resilience Act requirements.

### Source excerpt

Welcome to the latest CTRL-OS update! Find the last update from April here. If you don't know yet, CTRL-OS is a downstream distribution of NixOS designed to extend the release lifecycle to 5 years. It gives you a stable foundation with commercial support so you can build your products without having to maintain the packages you depend on. CTRL-OS 26.05 Released! The CTRL-OS 26.05 release is finally out. You can find the release blog post on our website. Or head over to our technical documentation and try it out. As long as NixOS 26.05 has community support, CTRL-OS 26.05 will be in the co-maintenance phase. In this phase, we will monitor our supported package set and contribute any security fixes back to NixOS. After community support ends, we enter the stability phase, and maintenance shifts completely to us. We've detailed this model on our blog. As of now, we support a small but useful package set. We'll share more details here soon, but our goal is to cover the usual packages you deploy on a server or embedded system, i.e., that dusty plastic box in the corner that quietly does its job for years. We actively monitor and backport CVEs for a core set of packages. To fund this work, commercial subscriptions provide SLA guarantees and cover custom package sets. While we aim to stay very close to NixOS 26.05, we will pull in important security fixes quickly to keep our SLAs. This creates a divergence that will automatically resolve itself once the security fixes make it to the NixOS release branch as well. Finally, to avoid a maintenance burden for the community, our CTRL-OS 26.05 release is lightly branded. By making it easy to identify a CTRL-OS system via nix-env -m, we ensure that bug reports originating from CTRL-OS users don't accidentally get filed against upstream NixOS, respecting the time and effort of upstream maintainers. No Cyber Resilience Act (CRA) Worries With the EU's CRA requirements taking effect this September, shipping embedded Linux products is

## How to Meet EU Cyber Resilience Act (CRA) Requirements

DevFeed: [How to Meet EU Cyber Resilience Act (CRA) Requirements](<https://devfeed.tech/articles/how-to-meet-eu-cyber-resilience-act-cra-requirements-29640.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/eu-cyber-resilience-act/>)

Author: info@goteleport.com (Maximilian Heck, Waldemar Kindler)

Published: 2026-07-01T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [Security](<https://devfeed.tech/topics/security.md>), [audit trail](<https://devfeed.tech/topics/audit-trail.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>)

Tags: [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [eu](<https://devfeed.tech/tags/eu.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [requirements](<https://devfeed.tech/tags/requirements.md>)

### AI overview

This tutorial explains how identity, access, encryption, and audit controls relate to EU Cyber Resilience Act requirements. It also discusses fragmented security toolchains, a compromised Trivy release, and infrastructure patterns such as short-lived cryptographic identities, hardware-rooted device trust, and unified audit trails.

### Source excerpt

Learn how to implement identity, access, and audit controls that meet EU Cyber Resilience Act compliance requirements.

## Understanding the EU Cyber Resilience Act (CRA)

DevFeed: [Understanding the EU Cyber Resilience Act (CRA)](<https://devfeed.tech/articles/understanding-the-eu-cyber-resilience-act-cra-13754.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/2026/03/esp32-cra-compliance/>)

Author: John Lee

Published: 2026-03-16T00:00:00Z

Content type: article

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [ESP32](<https://devfeed.tech/topics/esp32.md>), [Embedded Systems](<https://devfeed.tech/topics/embedded-systems.md>), [Espressif](<https://devfeed.tech/topics/espressif.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [cra-requirements](<https://devfeed.tech/tags/cra-requirements.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [digital-products](<https://devfeed.tech/tags/digital-products.md>), [embedded-systems](<https://devfeed.tech/tags/embedded-systems.md>), [esp-idf](<https://devfeed.tech/tags/esp-idf.md>), [esp32](<https://devfeed.tech/tags/esp32.md>), [espressif](<https://devfeed.tech/tags/espressif.md>), [eu](<https://devfeed.tech/tags/eu.md>), [iot](<https://devfeed.tech/tags/iot.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article explains how the EU Cyber Resilience Act applies to ESP32-based digital products, including connected devices, embedded systems, firmware, companion applications, and related cloud offerings. It outlines the CRA timeline, including vulnerability reporting obligations from September 2026 and core requirements from December 2027, and discusses compliance considerations for OEM manufacturers.

### Source excerpt

The EU Cyber Resilience Act introduces mandatory cybersecurity requirements for products with digital elements placed on the EU market. This blog outlines what the CRA means for ESP32-based products, the obligations for OEM manufacturers, and how Espressif will support customers in achieving compliance.

## Staying Ahead with ESP32 Security Updates

DevFeed: [Staying Ahead with ESP32 Security Updates](<https://devfeed.tech/articles/staying-ahead-with-esp32-security-updates-13755.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/2026/03/esp32-security-updates/>)

Author: John Lee

Published: 2026-03-05T00:00:00Z

Content type: article

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [ESP32](<https://devfeed.tech/topics/esp32.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>), [ESP-IDF](<https://devfeed.tech/topics/esp-idf.md>), [Espressif](<https://devfeed.tech/topics/espressif.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [esp-idf](<https://devfeed.tech/tags/esp-idf.md>), [esp32](<https://devfeed.tech/tags/esp32.md>), [espressif](<https://devfeed.tech/tags/espressif.md>), [iot](<https://devfeed.tech/tags/iot.md>), [lts](<https://devfeed.tech/tags/lts.md>), [ota](<https://devfeed.tech/tags/ota.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This article explains how the ESP32 ecosystem supports long-term firmware security and compliance under regulations such as the EU Cyber Resilience Act. It covers vulnerability management, secure OTA updates, Long-Term Support branches, the ESP-IDF Security Dashboard, and SBOMs for tracking affected components and patched versions.

### Source excerpt

This article explains how manufacturers can use the ESP32 ecosystem to build and maintain secure firmware over time, especially in light of new regulations like the EU Cyber Resilience Act. It highlights tools such as vulnerability dashboards, Long-Term Support branches, and secure OTA updates to ensure ongoing compliance and device security.

## Understanding the EU's Cyber Resilience Act (CRA)

DevFeed: [Understanding the EU's Cyber Resilience Act (CRA)](<https://devfeed.tech/articles/understanding-the-eu-s-cyber-resilience-act-cra-8226.md>)

Original publisher: [Read original article](<https://snyk.io/blog/understanding-the-eus-cyber-resilience-act-cra/>)

Author: Ben Desjardins

Published: 2025-01-22T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [snyk](<https://devfeed.tech/topics/snyk.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [eu](<https://devfeed.tech/tags/eu.md>), [executive](<https://devfeed.tech/tags/executive.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [sast](<https://devfeed.tech/tags/sast.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sca](<https://devfeed.tech/tags/sca.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

The article explains how the EU Cyber Resilience Act (CRA) establishes cybersecurity requirements for products with digital elements. It discusses secure-by-design practices, vulnerability handling throughout the product lifecycle, upcoming reporting and compliance deadlines, and the role of SAST, SCA, and software supply chain security.

### Source excerpt

Find out how the Cyber Resilience Act (CRA) sets new security standards for the EU and how Snyk can help simplify compliance with its developer-friendly tools.

## EU CRA: What does it mean for open source?

DevFeed: [EU CRA: What does it mean for open source?](<https://devfeed.tech/articles/eu-cra-what-does-it-mean-for-open-source-36392.md>)

Original publisher: [Read original article](<https://berthub.eu/articles/posts/eu-cra-what-does-it-mean-for-open-source/>)

Published: 2023-12-30T09:56:56Z

Content type: opinion

Language: en

Sources: [Bert Hubert's writings](<https://devfeed.tech/sources/bert-hubert-s-writings.md>)

Topics: [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Computing](<https://devfeed.tech/topics/computing.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [eclipse-foundation](<https://devfeed.tech/tags/eclipse-foundation.md>), [eu](<https://devfeed.tech/tags/eu.md>), [europe](<https://devfeed.tech/tags/europe.md>), [legal](<https://devfeed.tech/tags/legal.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [rules](<https://devfeed.tech/tags/rules.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [standards](<https://devfeed.tech/tags/standards.md>)

### AI overview

This opinion examines the final compromise text of the EU Cyber Resilience Act and its implications for open-source software. It discusses community concerns about applying the act's development, testing, auditing, and support requirements to open-source projects, while arguing that some criticism of the final text is unfounded.

### Source excerpt

The final compromise text of the EU Cyber Resilience Act is now officially available, and various open source voices are currently opining on it. This is a complex act and other parts of the open source world (like the Eclipse Foundation and NLNet Labs) have been hard at work to advocate with the EU and member states to get a CRA that is good for open source. I've also been highly critical.

## EU CRA: The compiler does not read the comments, but judges do read the Recitals

DevFeed: [EU CRA: The compiler does not read the comments, but judges do read the Recitals](<https://devfeed.tech/articles/eu-cra-the-compiler-does-not-read-the-comments-but-judges-do-read-the-recitals-36390.md>)

Original publisher: [Read original article](<https://berthub.eu/articles/posts/eu-cra-recitals-comments-compiler-judge/>)

Published: 2023-12-29T18:56:56Z

Content type: opinion

Language: en

Sources: [Bert Hubert's writings](<https://devfeed.tech/sources/bert-hubert-s-writings.md>)

Topics: [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [eclipse-foundation](<https://devfeed.tech/tags/eclipse-foundation.md>), [eu](<https://devfeed.tech/tags/eu.md>), [europe](<https://devfeed.tech/tags/europe.md>), [legal](<https://devfeed.tech/tags/legal.md>), [open-source](<https://devfeed.tech/tags/open-source.md>)

### AI overview

This emergency blog post discusses the final compromise text of the EU Cyber Resilience Act and argues that it mostly excludes open-source authors and programmers from its effects. It explains that the relevant provisions appear largely in the act's recitals and addresses possible misinterpretations of those provisions.

### Source excerpt

A bit of an "emergency blog post". The final compromise text of the EU Cyber Resilience Act is now available, and various open source voices are now opining on it. This is a complex act and other parts of the open source world (like the Eclipse Foundation and NLNet Labs) have been hard at work to advocate with the EU and member states to get a CRA that is good for open source.

## EU CRA and the Open Source Ecosystem: A Suggestion

DevFeed: [EU CRA and the Open Source Ecosystem: A Suggestion](<https://devfeed.tech/articles/eu-cra-and-the-open-source-ecosystem-a-suggestion-36388.md>)

Original publisher: [Read original article](<https://berthub.eu/articles/posts/eu-cra-best-open-source-security/>)

Published: 2023-11-12T13:22:46Z

Content type: opinion

Language: en

Sources: [Bert Hubert's writings](<https://devfeed.tech/sources/bert-hubert-s-writings.md>)

Topics: [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [eu](<https://devfeed.tech/tags/eu.md>), [europe](<https://devfeed.tech/tags/europe.md>), [legal](<https://devfeed.tech/tags/legal.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This commentary examines how the EU Cyber Resilience Act could affect open source projects and the broader open source ecosystem. It argues that commercial manufacturers relying on open source components should invest in their security, while regulation should avoid imposing compliance departments on individual open source developers. An update says a later agreed version of the Act appears to have addressed the concerns, making much of the original discussion historical.

### Source excerpt

UPDATE: On December 1st the EU agreed on a version of the Cyber Resilience Act that appears to have substantially addressed the concerns in the post below. Further analysis awaits, but do know that the text that follows is now mostly of historical interest! UPDATE 2: Here is the final compromise text of the Cyber Resilience Act. UPDATE 3: Here is an analysis of what it means for open source.

## Build affordable Secure connected devices with ESP32-H2

DevFeed: [Build affordable Secure connected devices with ESP32-H2](<https://devfeed.tech/articles/build-affordable-secure-connected-devices-with-esp32-h2-13821.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/build-affordable-secure-connected-devices-with-esp32-h2/>)

Author: John Lee

Published: 2023-05-11T00:00:00Z

Content type: article

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [ESP32](<https://devfeed.tech/topics/esp32.md>), [Security](<https://devfeed.tech/topics/security.md>), [Espressif](<https://devfeed.tech/topics/espressif.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [connectivity](<https://devfeed.tech/tags/connectivity.md>), [ecdsa](<https://devfeed.tech/tags/ecdsa.md>), [embedded-systems](<https://devfeed.tech/tags/embedded-systems.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [esp32](<https://devfeed.tech/tags/esp32.md>), [esp32-h2](<https://devfeed.tech/tags/esp32-h2.md>), [espressif](<https://devfeed.tech/tags/espressif.md>), [flash-encryption](<https://devfeed.tech/tags/flash-encryption.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [matter](<https://devfeed.tech/tags/matter.md>), [mcu](<https://devfeed.tech/tags/mcu.md>), [rsa](<https://devfeed.tech/tags/rsa.md>), [secure-boot](<https://devfeed.tech/tags/secure-boot.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article explains the ESP32-H2's hardware and software security features for connected devices, including Secure Boot, flash encryption, debug-interface protection, secure storage, memory protection, and device identity protection. It also describes RSA-PSS and ECDSA verification options, public-key storage and revocation, and the encryption of off-chip flash memory.

### Source excerpt

The awareness, as well as the associated concerns, about connected device security, is ever-increasing. With the European Union's Cyber Resilience Act also coming into effect soon, it has become ever so important to have security features built-in to the devices in hardware. The Espressif ESP32-H2 has been built to provide an affordable security solution to all and thus integrates a variety of security features.

## EU Cyber Resilience Act part two: Updates & Impracticalities

DevFeed: [EU Cyber Resilience Act part two: Updates & Impracticalities](<https://devfeed.tech/articles/eu-cyber-resilience-act-part-two-updates-impracticalities-36389.md>)

Original publisher: [Read original article](<https://berthub.eu/articles/posts/eu-cra-practicalities/>)

Published: 2023-03-23T15:51:39Z

Content type: opinion

Language: en

Sources: [Bert Hubert's writings](<https://devfeed.tech/sources/bert-hubert-s-writings.md>)

Topics: [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Software](<https://devfeed.tech/topics/software.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [Linux Kernel](<https://devfeed.tech/topics/linux-kernel.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>)

Tags: [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [eu](<https://devfeed.tech/tags/eu.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [linux](<https://devfeed.tech/tags/linux.md>), [linux-kernel](<https://devfeed.tech/tags/linux-kernel.md>), [politics](<https://devfeed.tech/tags/politics.md>), [programming](<https://devfeed.tech/tags/programming.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This follow-up commentary examines practical questions about how the EU Cyber Resilience Act might work, focusing on third-party components in hardware and software products. It discusses concerns about regulatory workability and possible effects on innovation, while noting the draft's due-diligence expectations for manufacturers.

### Source excerpt

This is a living document - I'd normally spend a few days polishing everything, but since CRA talks are ongoing right now, there's simply no time for that. Check back frequently for updates! Also please let me know urgently on bert@hubertnet.nl if you think I'm reading things incorrectly! As a follow-up to my earlier post on the EU Cyber Resilience Act, here I'd like to address some practicalities: how would it actually work.

## How the EU Cyber Resilience Act would set cybersecurity requirements for software and connected products

DevFeed: [How the EU Cyber Resilience Act would set cybersecurity requirements for software and connected products](<https://devfeed.tech/articles/the-eu-s-new-cyber-resilience-act-is-about-to-tell-us-how-to-code-36391.md>)

Original publisher: [Read original article](<https://berthub.eu/articles/posts/eu-cra-secure-coding-solution/>)

Published: 2023-03-14T08:13:10Z

Content type: opinion

Language: en

Sources: [Bert Hubert's writings](<https://devfeed.tech/sources/bert-hubert-s-writings.md>)

Topics: [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Code](<https://devfeed.tech/topics/code.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [business](<https://devfeed.tech/tags/business.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [code](<https://devfeed.tech/tags/code.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [eu](<https://devfeed.tech/tags/eu.md>), [europe](<https://devfeed.tech/tags/europe.md>), [firefox](<https://devfeed.tech/tags/firefox.md>), [firewalls](<https://devfeed.tech/tags/firewalls.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [innovation](<https://devfeed.tech/tags/innovation.md>), [linux](<https://devfeed.tech/tags/linux.md>), [microcontrollers](<https://devfeed.tech/tags/microcontrollers.md>), [public-key](<https://devfeed.tech/tags/public-key.md>), [requirements](<https://devfeed.tech/tags/requirements.md>)

### AI overview

This commentary examines the EU Cyber Resilience Act (CRA), which would establish essential cybersecurity requirements for nearly all software and hardware with digital elements distributed in Europe. It discusses proposed secure-coding standards, third-party audits for certain critical products, and potential fines for non-adherence.

### Source excerpt

First a round of thanks for the many people in industry and government who provided valuable links, background and insights! I could not have done this without your help! If you spot any mistakes, or have suggestions, please do contact me on bert@hubertnet.nl The EU's new Cyber Resilience Act is admirable in its goal. And the EU is not alone in thinking something needs to be done about the dreadful state of security online - the Biden administration has just released its National Cybersecurity Strategy that has similar aims.