Doc McConnell, Head of Policy and Compliance, Finite State:
“The release of final draft standards from ETSI is great news for product manufacturers in these 17 verticals that cover many of the “important” products with digital elements defined in the Cyber Resilience Act. Seeing these documents makes it easier to concretely evaluate existing products to see where they align with the CRA requirements, and where manufacturers will need to do additional work prior to the December 2027 deadline.
“I expect we’ll see manufacturers looking for help in the immediate future to evaluate their existing products to get a baseline of their compliance status, as well as looking for partners who can help them engineer future products in ways that are CRA-compliant before they ever hit the market.”
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“The CRA’s Article 14 vulnerability reporting obligation starts September 11. Manufacturers will have 24 hours to submit an early warning for actively exploited vulnerabilities. Meeting that window in practice means knowing what components ship in every product, which versions are affected, and who owns remediation. I’ve watched that question consume most of the response time during live incidents, where teams dig through repositories and old release manifests while the clock runs.
“SBOMs built for incident response are produced automatically during builds, tied to specific product versions, retained across releases, and queryable when a new CVE drops. A document generated once for an auditor can’t answer those questions under a 24-hour clock. SBOMs are becoming incident-response infrastructure.
“AI-accelerated vulnerability discovery compounds the pressure. AI systems are already demonstrating the ability to discover previously unknown vulnerabilities in production software. As researchers run vulnerability-discovery agents in parallel, finding potential vulnerabilities can scale faster than the engineering processes required to triage and remediate them. When discovery outpaces your ability to identify affected products, component visibility becomes the bottleneck.
“The 17 ETSI draft standards now entering formal approval begin translating the CRA’s SBOM obligations into technical requirements. They don’t yet carry the presumption of conformity under Article 27, which requires publication in the Official Journal. Treat them as a gap analysis baseline.”
John Strand, Owner, Black Hills Information Security, Inc.:
“In so many ways, it seems like Europe is getting this a little bit faster than we are in the United States. This is exactly the type of guidance and requirements we need for companies building Internet of Things devices, appliances, routers, and all of the other technology that ends up connected to our networks.
“There need to be baseline security requirements built into these products from the very beginning. And hopefully, this continues to expand so manufacturers aren’t just responsible for security when a product ships. They need to maintain responsibility for the security of those devices throughout the lifespan of the product.”
Seemant Sehgal, Founder & CEO, BreachLock:
"Europe is doing something manufacturers have resisted for decades, which is making security a condition of market access. The seventeen standards moving through ETSI are essentially a translation layer, converting a legal obligation into something an engineering team can actually act on. What strikes me about the CRA requirements is how foundational they are.
“Encrypted communications, secure defaults, a documented software bill of materials, a defined path for delivering updates. These are not ambitious asks. They are baseline hygiene that the industry has been slow to standardize because there was no hard deadline and no real consequence for skipping it. December 2027 creates both of these.
“The question manufacturers should be considering now is how much of their existing product architecture was built with the assumption that they never would have to meet specific security requirements."






