Proposal(s) title:
- Generic Secure Update Package: Threats, Requirements and Assessment cases for CRA standards
Proposal(s) topic:
Cybersecurity/Network and Information security
Societal, Economic or Technological Impacts:
Contribution impact:
This work is expected to improve the security and resilience of products with digital elements by providing a consistent, assessable approach to secure updates across CRA product categories. For the EU, it supports coherent implementation of the Cyber Resilience Act, reduces fragmentation between vertical standards and strengthens trust in software and firmware maintenance. European SMEs should benefit from clearer compliance expectations, reusable implementation patterns and more predictable assessment evidence, reducing duplicated engineering and certification effort.
-
With this fellowship, deliver a reusable, cross-domain “Secure Update Package” comprising: (i) a structured threat catalogue, (ii) a baseline set of security requirements, and (iii) conformity assessment cases. The output is designed to be directly reusable by CRA standards, reducing fragmentation. It's especially related to CEN-CENELEC JT013091 (PT2) and vertical standards as well as ETSI EUSR vertical standards.
> Primary deliverable: “CRA – Secure Update Package for Vertical Standards”
Read more
Standards Development Organisation:

