The Raspberry Pi Podcast The Raspberry Pi Podcast

The EU Cyber Resilience Act: What It Means for Raspberry Pi (and You)

Sep 11, 2026 · 38m

Summary

This episode features James Hughes and Matthew Lear discussing the EU’s Cyber Resilience Act and its impact on manufacturers using Raspberry Pi. They cover key deadlines, including the September 2025 reporting requirements and the 2027 full enforcement, emphasizing the shift of security responsibility to product makers. The guests explain how to use Raspberry Pi’s secure boot, encryption, and SBOM tools to build compliant, immutable images. They also detail the use of Raspberry Pi Connect for secure A/B updates and the importance of monitoring CVEs to mitigate exploited vulnerabilities.

Topics discussed

Introduction and guest introductions Overview of CRA scope and key dates Legislative intent and product risk categories Core security principles: trusted boot and encryption Raspberry Pi tools for secure image generation Manufacturer obligations and market placement Vulnerability reporting timelines and patching Challenges for existing device fleets Software Bill of Materials (SBOM) and auditing Immutable images and vulnerability correction Raspberry Pi Connect for remote fleet management A/B boot systems for safe updates Tracking CVEs and public vulnerability lists Distinction between known and exploited vulnerabilities Conducting cybersecurity risk assessments Upstream Debian maintenance and patching Summary of compliance steps for manufacturers Benefits of robust update mechanisms Final summary and contact information
Listen ad-free on Castria