CyberSecurity Resilience Act (CRA) in Practice for IoT Devices: Getting Ready for the NIS2
Antonio J. Jara, Iris Cuevas Martínez, Jaime Sanchez Sanchez · 2024
Internet of Things (IoT) requires advanced Cybersecurity features to satisfy the newly proposed Cyber Resilience Act (CRA) in the context of satisfying the Network and Information Security 2 Directive (NIS2). This work is supported by INCIBE (Spanish National Institute for Cybersecurity) illustrates how the CRA proposal integrates with other EU cybersecurity legislation and emphasize its interaction with the NIS2 Directive. The interplay between these two regulations is studied for the definition of the best practices and new features that must be included in IoT-driven solutions. Practical examples from Libelium's experience in the IoT sector demonstrate how their practices align with CRA requirements, focusing on the release of Libelium One, the first product designed to meet CRA standards for critical infrastructures, and key innovations as LwM2M cybersecurity probes, and the extension of SIEMs with an IoT monitoring and rules collections for specific protocols being used in NB-IoT, 4G and LoRa. By detailing Libelium's approach for developing and deploying IoT solutions that satisfy both CRA and NIS2 directives. This case study underscores the real-world applicability of the CRA framework and highlights the benefits and challenges faced by IoT manufacturers in achieving regulatory compliance.