CRA and Cryptography: The Story Thus Far

No ratings

Presented at Real World Crypto 2026 by

We report on our experiences with the ongoing European standardization efforts related to the EU Cyber Resilience Act (CRA) and provide interim estimates on the direction that European cryptography regulation may take, particularly concerning the algorithm ``allow list'' and the enforcement of the PQC transition in products. We also outline some of the risks associated with the partially closed standardization process: Lack of public review leading to lower quality, impact minimization by vendors, and increased potential for backdoors. The Cyber Resilience Act came into effect in December 2024, and its obligations will fully take effect for makers of "products with digital elements" (most smart consumer electronics and many types of software) from 2027. CRA compliance is a requirement for obtaining the CE mark and a prerequisite for selling products in the European Single Market, which comprises 450 million people. The CRA has a wide-ranging set of security requirements, including security patching and direct cryptographic requirements (data integrity, confidentiality for data at rest and data in transit). However, the Cyber Resilience Act itself is a legal text devoid of technical detail -- it does not specify the type of cryptography deemed appropriate to satisfy its requirements. The technical implications of CRA are expected to be detailed in approximately 40 new standards from the three European standardization organizations, CEN, CENELEC, and ETSI. While the resulting ETSI standards can be expected to be available for free, the CEN and CENELEC standards will probably not be available to the public before they are finished, and even then, only for a per-reader license fee. This, despite recent legal rulings asserting that product security and safety standards are part of EU law due to their legal effects. Taking a recent example of such standards, we observe that the actual cryptographic requirements set out in EN 18031 series, the Radio Equipment Directive (RED) harmonised standard from 2024 (which is in many ways a direct predecessor of CRA), allow vendors to take a no-foresight approach where weak cryptography may be considered ``best practice'' right until exploitation is feasible. Recognizing the weakness of the previous ``best practice'' definition and additional requirements such as the EU Post-Quantum Cryptography transition roadmap, CRA standardization working groups are currently moving towards a model where approved cryptography is listed by the European Cybersecurity Certification Group (ECCG) as a single source of truth. CRA products may still support other cryptographic mechanisms, but only approved algorithms are permitted as safe defaults.