logoalt Hacker News

lnsrutoday at 10:33 AM1 replyview on HN

How good is your employer prepared for Cyber Resilience Act?


Replies

birdsongstoday at 10:52 AM

Fine. We're already meeting the goals for free by virtue of building a secure product and infrastructure from the start. (Read: a good product.) When risk assessments and certs are required and roll out (1.5 years from now), we'll just get a contractor or two on board for a few months to do it, and to set up the processes to keep it rolling. It's in the budget.

People act like these are industry shattering requirements, but hard tech is already subject to a plethora of requirements we have to handle every day. We will always have some kind of process for CE certification, battery safety requirements, GDPR, or open source licensing and toolchain access, etc, etc. This is just another (honestly, minor) process to roll in with the rest of them.