
#024: Shipping Firmware Under the CRA: Nicolas Schieli on the Questions Everyone’s Asking, and the Ones They Should Be Link:
In this Coredump Session, François Baldassari and Chris Coleman are joined by Nordic Semiconductor VP of Product Security, Nicolas Schieli, to break down what the EU Cyber Resilience Act (CRA) means for teams building connected products. With the CRA’s first reporting requirements now in effect, they discuss what companies need to do today, how the 24-hour vulnerability reporting window works, which products fall within scope, and what changes when the broader requirements take effect in December 2027. The conversation also covers threat modeling, secure development processes, product classifications, SBOMs, long-term support, OTA updates, secure boot, open source dependencies, and how AI can fit into CRA workflows. Key Takeaways: The CRA’s vulnerability reporting requirements are already in effect, including a 24-hour reporting window for severe incidents or actively exploited vulnerabilities. Companies need a documented process for receiving, assessing, and responding to vulnerability disclosures. Checking a security inbox once a week is not enough for the CRA’s reporting timelines. The CRA applies broadly to products with digital elements placed on the European market, including hardware, software, firmware, and some devices that are not connected to the internet. Full compliance requirements take effect in December 2027 and include capabilities such as delivering vulnerability fixes, verifying that code has not been tampered with, protecting interfaces, and securing sensitive data. Threat analysis and risk assessment will need to become a formal part of product development rather than something engineering teams handle informally. Product classification determines how companies demonstrate compliance. Default-class products can generally self-assess, while higher-risk classes require additional third-party assessment or certification. Manufacturers need visibility into the software and hardware components inside their products so they can continuously monitor dependencies for vulnerabilities. Products placed on the market must declare a support period of at least five years, during which manufacturers are expected to track vulnerabilities and provide fixes. Documentation from chip, software, and other technology vendors can support a company’s compliance evidence, but the manufacturer placing the final product on the market remains responsible for that product. Watch this episode on YouTube Follow Memfault LinkedIn Bluesky Twitter Other ways to listen: Apple Podcasts iHeartRadio Amazon Music GoodPods Castbox Visit our website


