Bottom line: SMEs often lack the organizational and technical resources to meet CRA requirements within the prescribed timeframe.
Small and medium-sized enterprises in the EU are facing significant challenges in preparing for the Cyber Resilience Act (CRA), according to a recent analysis by the European Union Agency for Cybersecurity (ENISA).
The Cyber Resilience Act will become mandatory regulation for product and solution providers supplying the EU internal market. The regulation requires manufacturers of IoT devices, cybersecurity components and critical infrastructure software to implement binding security requirements in design, production and maintenance. Large corporations are already implementing compliance processes in some cases – SMEs, however, face a transformation challenge.
Many small and medium-sized enterprises report resource shortages, lack of clarity on concrete compliance requirements and insufficient capacity in IT security and product development. Added to this are uncertainties in interpreting the regulatory scope and technical standards. Particularly critical: SMEs often lack an established governance framework for documenting security measures, which becomes necessary during audits and certifications.
CISOs in affected SMEs should therefore conduct a readiness analysis early on to identify implementation gaps. ENISA recommends, among other measures, mentoring programmes between large corporations and SMEs, public self-assessment toolkits and regulatory transition periods to distribute compliance burdens. The final application of the CRA is planned for 2027.
Source: www.enisa.europa.eu · Published
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.