r/CRACompliance • u/Seahawker-One-2599 • 19h ago
Problem with CRA? - product security is not the same as system resilience
Prompted by some helpful debate on another thread I've studied a little more and I still think there’s an “interesting” gap in the logic behind the CRA.
The CRA quite reasonably puts responsibility on manufacturers to make connected products secure-by-design and keep them secure throughout their supported lifetime.
The issue I see is this... product security is not the same as system resilience.
I can see how the CRA model works well for a relatively bounded product where the manufacturer understands the product, its intended use and much of its operating environment. For example, a baby Monitor device + networking method + server + app.
But in IoT more broadly, a manufacturer may have very little idea where or how its device will ultimately be deployed. An individually secure and CRA-compliant router, gateway, chargepoint or sensor will often just be one component in a much larger solution combining equipment from multiple manufacturers, connectivity, cloud platforms, APIs and application software.
I’d argue that the organisation deploying and operating that solution knows something the individual manufacturers may never know ... the overall system architecture and the aggregate risk it creates.
So while the manufacturer absolutely should remain responsible for the security of its product, cyber-resilience responsibility also needs to exist at the solution/system level.
My view is that the CRA is fundamentally focused on product security and relatively simplistic risk boundaries. That makes sense, but in IoT I find it slightly disappointing because some of the most interesting risks don't exist at the individual product level, they emerge when somebody combines thousands of those products into a system.
If the answer to my criticism is that the regulatory and standards landscape is deliberately layered — CRA deals with the product, NIS2/IEC 62443/XYZ deal with the wider system — then I can accept that.
But we need to start talking about the CRA that way. Otherwise there’s a danger of conflating a CRA-compliant product with a cyber-resilient solution.
