The EU Cyber Resilience Act: What It Means for Raspberry Pi (and You)
Sep 11, 2026 · 38m
Summary
This episode features James Hughes and Matthew Lear discussing the EU’s Cyber Resilience Act and its impact on manufacturers using Raspberry Pi. They cover key deadlines, including the September 2025 reporting requirements and the 2027 full enforcement, emphasizing the shift of security responsibility to product makers. The guests explain how to use Raspberry Pi’s secure boot, encryption, and SBOM tools to build compliant, immutable images. They also detail the use of Raspberry Pi Connect for secure A/B updates and the importance of monitoring CVEs to mitigate exploited vulnerabilities.
Topics discussed
Introduction and guest introductions
Overview of CRA scope and key dates
Legislative intent and product risk categories
Core security principles: trusted boot and encryption
Raspberry Pi tools for secure image generation
Manufacturer obligations and market placement
Vulnerability reporting timelines and patching
Challenges for existing device fleets
Software Bill of Materials (SBOM) and auditing
Immutable images and vulnerability correction
Raspberry Pi Connect for remote fleet management
A/B boot systems for safe updates
Tracking CVEs and public vulnerability lists
Distinction between known and exploited vulnerabilities
Conducting cybersecurity risk assessments
Upstream Debian maintenance and patching
Summary of compliance steps for manufacturers
Benefits of robust update mechanisms
Final summary and contact information
Listen ad-free on Castria