Paper 2025/2092

CRA and Cryptography: The Story Thus Far

Markku-Juhani O. Saarinen, Tampere University, Finland
Abstract

We report on our experiences with the ongoing European standardisation efforts related to the EU Cyber Resilience Act (CRA) and provide interim (November 2025) estimates on the direction that European cryptography regulation may take, particularly concerning the algorithm ``allow list'' and PQC transition requirements in products. The CRA has a wide-ranging set of security requirements, including security patching and the use of cryptography (data integrity, confidentiality for data at rest and data in transit). However, the Cyber Resilience Act itself is a legal text devoid of technical detail -- it does not specify the type of cryptography deemed appropriate to satisfy its requirements. The technical implications of CRA are being detailed in approximately 40 new standards from the three European standardisation organisations, CEN, CENELEC, and ETSI. While the resulting ETSI standards can be expected to be available for free even in the drafting stage, the CEN and CENELEC standards will probably require a per-reader license fee. This, despite recent legal rulings asserting that product security and safety standards are part of EU law due to their legal effects. We outline some of the risks associated with the partially closed standardisation process, including active impact minimisation by vendors concerned with engineering costs, a lack of public review leading to lower technical quality, and an increased potential for backdoors. Taking a recent (2024) example of cryptographic requirements in such standards, we observe that the definitions and language in the Radio Equipment Directive (RED DA) harmonised standard (EN 18031 series) may allow vendors to take an approach where weak cryptography is considered ``best practice'' right until exploitation is feasible. Recognising recent developments such as the EU Post-Quantum Cryptography transition roadmap, many CRA standardisation working groups are moving towards a ``State-of-the-Art Cryptography'' (SOTA Cryptography) model where approved mechanism listings are published by the European Cybersecurity Certification Group (ECCG). CRA-compliant products may still support other cryptographic mechanisms, but only SOTA is permitted as a safe default for Internet-connected products.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Published elsewhere. Minor revision. SSR 2025 -- Security Standardisation Research Conference. Passau, Germany, 04-05 December 2025. https://www.uni-passau.de/ssr2025
Keywords
CRACyber Resilience ActRED-DAAgreed Cryptographic MechanismsCryptographic AgilityPQC Transition
Contact author(s)
markku-juhani saarinen @ tuni fi
History
2025-12-12: last of 2 revisions
2025-11-13: received
See all versions
Short URL
https://ia.cr/2025/2092
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2092,
      author = {Markku-Juhani O. Saarinen},
      title = {{CRA} and Cryptography: The Story Thus Far},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2092},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2092}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.