EU CRA Webinar Q&A

On December 18th, we held a webinar entitled “The EU Cyber Resilience Act – Training for Embedded Engineers”.

It was a well attended session, and the recording is available here (if you already registered, you should be able to re-use your attendee link).

If you’re new to the topic and have arrived via Google, you could start here: EU CRA 101

At the end, I very briefly mentioned how Direct Insight is ensuring that our products and services are CRA compliant – and that includes being able to support Secure Boot, and OTA updating. We’ve been particularly focused on a production-ready module based on i.MX93 and this i.MX8M Mini SODIMM SoM. in terms of preparation. No doubt our S32G, Layerscape and ST32M solutions will come next. If you’re thinking of microcontrollers, we can send you in the right direction if you ask.

We’re also planning some Cyber Resilience Act training, so please sign up for our CRA-specific mailing list (link on the right) if you would like to be informed when that web page goes live.

Finally, there were a number of questions, and I didn’t get to all of them during the webinar, so I am publishing them below. It’s not too late to ask additional questions – just contact me and I’ll add them to the list.

Q./ What is the Notified Body role within the CRA?

A./ A “Notified Body” has to be registered with the EU Commission and be issued a reference number. Products not subject to “Module A” route conformity assessment ( and therefore going via an internal procedure performed by the manufacturer) have to be assessed by, or report the assessment to, a Notified Body, depending on the assessment route which depends on the category (Critical, Important I/II).

In short, products in the “Everything Else” category – that’s most products – qualify for the Module A route, and Important Class I products may also follow this route subject to particular requirements, in which case no need for involvement of a Notified Body.

Q./Looking at the UK market, you mentioned the “Cyber Resilience and Security Bill”. Do you have a timeline and expected extend of it compared to the EU CRA?

There is currently no timeline for this. If a harmonised standard emerges in support of the CRA, then a UK law is likely to just rubber stamp the provisions of that standard in my view – or alternatively may conceivably be less prescriptive in a nod to the US’s far less aggressive regulatory stance. That’s a political decision. I think the potential emergence of a harmonised standard is the thing to look out for. At the moment, this is being considered by bodies such as BSI and CENELEC. Without that, existing standards such as EN 303 645, IEC 62443 and EN 18031 are going to provide the baseline for assessment.

Q./ Very interesting webinar, especially to explain the terms from EU 😉 It is mainly oriented on Software. What are the implications for Hardware ? I’m thinking about PSA certified chipset (SoC), need for Secure Element or Cryptocell. Is a module considered safer from a CRA point of view compared to chip-down solution. when do you think CE certification will integrate CRA, if it happens.

A./ As an electronics engineer, I do try to avoid a software-centric approach – sorry if it came over that way. If you’re going to implement secure boot and encryption – and it’s hard to see how that wouldn’t be required – then the level of integrity of the hardware secure element (and the power of supported encryption) are obviously important. How far you need to go depends on the risk assessment. PSA certification level is a good guide and assurance for this – we’re currently working on customer projects with NXP i.MX93 which has PSA level 3 certification and that’s very helpful.

I don’t think a module is automatically safer from a CRA perspective, but I do think it’s potentially an easier route to conformity. When developing at the SoC level you inevitably integrate a lot of 3rd party code of uncertain origin – such as device drivers during the BSP effort, and hence add significantly to your Software Composition Analysis and CVE mitigation task. With a module, all that is done, and presumably compliant, and you only have to worry about your application plus any middleware.

Processors and modules are not currently CE marked, but will be once CRA compliant. I don’t expect that to happen just yet, but it’s something to look out for, and a perfectly valid question for vendors.

Q./ The CRA wording itself defines ‘placing on the market’: ‘placing on the market’ means the first making available of a product with digital elements on the Union market; So it seems to refer to the first time the product is released, but doesn’t say anything about ‘Making available on the market’ which is the continuation of the sales of the product. So it still appears that existing products are exempt. Can you please clarify?

A./The bottom line here is that the EU Blue Guide is considered absolutely authoritative in its definition of the special terms such as “making available on the market” and “placing on the market” used in EU Regulations. Clearly, in day-to-day English, placing something on the market is shorthand for launching a new product type. However, the Blue Guide defines the term differently. Here is the second paragraph of Blue Guide 2.3 (as at https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/):

“As for ‘making available’, the concept of placing on the market refers to each individual product, not to a type of product, and whether it was manufactured as an individual unit or in series. Consequently, placing on the Union market can only happen once for each individual product across the EU and does not take place in each Member State. Even though a product model or type has been supplied before new Union harmonisation legislation laying down new mandatory requirements entered into force, individual units of the same model or type, which are placed on the market after the new requirements have become applicable, must comply with these new requirements.”

So our colloquial English understanding of “placed on the market” holds in terms of the introduction of a new product. However, it diverges in that in the Blue Guide definition, it’s placed on the market repeatedly every time a unit is shipped. In the colloquial sense placing on the market happens once per product line, in the Blue Guide definition, it happens once per individual unit.

[Note: I am not a lawyer and this is not legal advice. I strongly recommend obtaining legal advice in case of doubt on any point. Having an EU-specialist lawyer provide due diligence on the interpretation of CRA and other EU regulations is a sensible step for anyone embarking on significant investment in compliance.]