No. 76: How Much CRA Compliance Is Needed for Legacy Products?
Different answers to the title question. VDMA: None. Commission Guidance: nearly full. CRA and Blue Guide: partial. In practice: none if no changes; full if feature updates; otherwise by addressing one risk after the other in an SDR.
Read next
A Pragmatic Approach to CRA Risk Assessment
In less than 30 minutes, I can explain a pragmatic approach how to model the threats of an embedded system, assess the cybersecurity risks and document the risks in security decision records (SDRs). Here is the video from my talk at the Torizon CRA Summit in Munich.
How Can Manufacturers Address and Remediate 1000+ CVEs?
Fixing 1000+ CVEs one by one is too costly. Filtering them is arbitrary and might miss important ones. Making the exploitation of hundreds of CVEs unlikely by multiple security measures in one go is nothing else but defence in depth!