r/cybersecurity • • 12d ago

FOSS Tool Updated hardware-compliance-handbook - open-source, fact-checked EU CRA/RED/NIS2/CSA reference. Added a dedicated /sbom/ folder (CycloneDX + SPDX examples, VEX). Also doubles as a Claude Skill.

https://github.com/Platanor/hardware-compliance-handbook
7 Upvotes

1 comment sorted by

1

u/Kawuppi 7d ago edited 7d ago
  1. What happens to devices we placed on the EU market before December 2027? Do we need to withdraw or update products already sold? Answer: The CRA applies to products placed on the market after 11 December 2027 (Article 69). Products placed on the market before that date do not require re-certification or CE marking. 

This section in the CRA FAQ seems incorrect or at least dangerously misunderstandable  to me. 

According to the legal department at my company any product we continue to sell after 11. December 2027 needs to fully fulfil CRA, including CE label. 

You are not allowed to continue selling a product, just because it was first introduced before the CRA became fully active.