3 ms·
I recommend actually reading the CRA[1] the requirements for non-critical software are easy to follow. If your product does not fall into the categories describ
by Lariscus 2y ago
I recommend actually reading the CRA[1] the requirements for non-critical software are easy to follow.
If your product does not fall into the categories described in Annex III you are making non-critical software.
The requirements are described in Annex IV, V and VI. You must do a conformity assessment and provide a declaration of conformity. For non-critical software you can do the assessment yourself see the first five points in Annex VI. The only thing that maybe requires a bit of effort is that you must write some technical documentation including a cybersecurity risk assessment. For critical software the process is more involved because it requires certification by a "notified body".
If a startup in the EU fails because they have to write a bit of documentation once in a while they deserve to fail. Also if a startup wants to create security relevant software I expect that they follow some security standard and the CRA makes sure of that.
None of these requirements are something only a billion dollar company can do.
[1] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:52022PC0454 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
- temac 2y agoYou could say all of that of other things e.g. the MDR, where the end result in practice is complete crap. The system of "notified bodies" is commercial bureaucracy with random efficiency. If an agency wants to audit me, just dot it. The FDA does, with lower delays than commercial EU notify bodies... (right now the EU is accumulating more and more years of delay on putting medical devices on the market, even locally developped)