fukami
Brussels Zinneke, CRA wonk, working at CrabNebula on European standards development. suppoirting manufacturers with product conformity.
.
Session
The Cyber Resilience Act (CRA) is EU product legislation that lists categories of important and critical products. Standards for these categories are being developed by ETSI and CEN-CENELEC. Boot managers are one of them (Annex III, Class I): a manufacturer who applies the harmonised standard can self-assess conformity, otherwise a notified body has to be involved.
Reporting obligations have applied since 11 September 2026 and the product standards are entering their final stage. As rapporteur of ETSI EN 304 623, I give an overview of where things stand and which issues remain open, including what counts as a boot manager in this context in the first place.
Firmware is often built from open-source components that were never placed on the market on their own. The talk closes with an idea for how device manufacturers and integrators can meet their due diligence obligation for such components (CRA Art. 13(5)).