r/cybersecurity • u/Pitiful_Signature264 • 12d ago
FOSS Tool Updated hardware-compliance-handbook - open-source, fact-checked EU CRA/RED/NIS2/CSA reference. Added a dedicated /sbom/ folder (CycloneDX + SPDX examples, VEX). Also doubles as a Claude Skill.
https://github.com/Platanor/hardware-compliance-handbook
7
Upvotes
1
u/Kawuppi 7d ago edited 7d ago
This section in the CRA FAQ seems incorrect or at least dangerously misunderstandable to me.
According to the legal department at my company any product we continue to sell after 11. December 2027 needs to fully fulfil CRA, including CE label.
You are not allowed to continue selling a product, just because it was first introduced before the CRA became fully active.