Ask HN: Is anyone else preparing for the EU Cyber Resilience Act?
I run a one-person GmbH in Germany. I am thinking about selling firmware for an off-the-shelf handheld - offline, no WiFi, no network stack compiled in at all, updates by reflashing over USB. I don't sell hardware, just software.
Turns out that the EU Cyber Resilience Act applies to me. The EU starts to handle software products similar to hardware products and the CRA regulates that (and from a customer's standpoint - rightfully so!).
Reporting duties start this September; everything else in December 2027. So I spent some time reading the sources rather than the commentary: the Regulation itself [1], and the Commission's guidance of 27 July 2026 [2] (C(2026) 5252, around 80 pages with 67 worked examples, explicitly aimed at SMEs).
This is what I found out so far, and this is where I'd like to be corrected:
1. Selling software now works like selling hardware. Same regime - technical file, declaration of conformity, CE marking on a piece of software. I'd assumed CE was a hardware thing; with the CRA not anymore.
2. I can't escape it by giving the software away. The exemption is for open source supplied outside commercial activity - free isn't the same as non-commercial. Firmware I publish to support a product I sell is plainly commercial, whatever I charge for it.
3. There's no size threshold. A one-person company carries the same obligations as a large one. Article 33 is titled "Support measures for microenterprises and small and medium-sized enterprises" and every provision in it is help, not exemption.
4. But the actual work is small. My product isn't in Annex III, so it's self-assessment: no notified body, no fee, nothing filed, nobody approves anything. The work seems to be a handful of documents I write once. You basically stick the CE label on by yourself.
5. But there is Art. 13(9). Every security update you ship has to stay available for 10 years after you issue it, or the rest of the support period, whichever is longer. That's a serious amount of time into the 2040s for a product launched in 2027, maybe sold only once.
6. Reporting obligations don't end when support does. The guidance is explicit (para 210): vulnerability handling stops with the support period, reporting continues afterwards.
I'll stop here, but there's a couple more implications.
Ah, and before you ask: it doesn't matter where you live, it matters that you sell to the EU.
In a nutshell: I didn't find any 'indie' sources dealing with these matters, so my main question is - is anyone else preparing for this scenario? If so, how do you handle it? Especially interested in anyone who has actually been through this at a small scale, or anyone from a market surveillance authority.
[1] https://eur-lex.europa.eu/eli/reg/2024/2847/oj
[2] https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation
We are having these discussions daily at the moment. We have a nice collection of content from the Torizon CRA Event in Munich, and more online and offline events are coming. https://www.torizon.io/events/torizon-cra-summit-online I work for Toradex, and most of our customers need to comply; many of them are small and without big security teams. And we ourselves also have to comply.
We talk about these topics almost daily. If you are interested, here is a collection of the talks from the Torzion CRA Summit in Munich. Let me know if you need more help: https://www.torizon.io/events/torizon-cra-summit-online
You should look for security frameworks based on this law. A common example is SOC2; the compliance audit has you compiling documents and recording SLAs long before any security incident might require it. There are many open source tools that you can use to track compliance in the various frameworks on your own. One of them may have an update for this new law.
Thanks. The CRA's own version of what you are describing is harmonised standards: Art. 27 gives you a presumption of conformity with the Annex I requirements if you follow one whose reference has been published in the Official Journal.
The catch is that they do not exist yet. M/606 covers around 41 standards and was accepted by CEN, CENELEC and ETSI in 2025, but the Commission's July 2026 draft amendment pushed the deadlines back two months: the two core horizontal standards (secure development, vulnerability handling) are now due 31 October 2026, the verticals 31 December 2026, and the remaining horizontal ones October 2027, about a year before full application.
And delivery is not the same as availability - a standard only gives you the Art. 27 presumption once its reference is cited in the Official Journal. Nothing has been cited for the CRA yet: the Commission's harmonised standards site lists 40 pieces of legislation and the CRA is not among them.
On tooling specifically: the Open Regulatory Compliance Working Group (orcwg.org) runs a CRA hub on GitHub, closest thing I have found to what you describe.
I wish it were less complicated. :)
Check ReARM we're building for durable tracking of releases, software updates and fulfilling 10+ years obligations - https://rearmhq.com
Hey Mate, we at Vulert have helped many companies to do part of it, i.e., keeping their software dependencies monitored for current and upcoming vulnerabilities without any code access or installation.
Feel free to reach out if it interests you.
dawood@vulert.com