Logs, Not Logic: Rethinking Audit Trail Requirements for Tiny On-Device Security Engines
Ziad Salah · Zenodo (CERN European Organization for Nuclear Research) · 2026
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) requires that products with digital elements “provide security related information by recording and monitoring relevant internal activity” (Annex I, Part I, point 2(l)). This requirement is frequently discussed, in industry commentary, as if it implied disclosure of a security engine’s internal decision logic. It does not: the text describes activity logging (access and modification events), not algorithmic transparency. This paper argues that the real risk sits one level down, at the standardization layer, where “demonstrability” of compliance could be operationalized in ways that go beyond the statutory text and effectively force disclosure of detection logic. This is a structural concern specifically for compact, deterministic, fully auditable engines: their very transparency-by-design makes them easier to reverse-engineer than opaque, large models if internal logic is exposed on request. The paper proposes a tiered compliance model that satisfies the literal text through standard activity logging by default, reserving deeper, logic-level auditability for a narrow set of high-criticality deployments under restricted, non-public access. A small open-source reference implementation (Planck-99, an integer-only, deterministic on-device malware classification engine) is used throughout as a concrete illustration of the engineering trade-offs discussed. Disclosure: the author is the developer of the reference implementation discussed (Planck-99) and discloses a commercial interest in its adoption. This is an independent technical position paper and is not a formal submission on behalf of any standards body.