{"id":32558,"date":"2025-12-16T13:54:31","date_gmt":"2025-12-16T13:54:31","guid":{"rendered":"https:\/\/preprod25.numeum.fr\/cra-nis2-dora-how-to-turn-onboard-cybersecurity-compliance-into-a-competitive-advantage\/"},"modified":"2025-12-16T14:26:50","modified_gmt":"2025-12-16T14:26:50","slug":"cra-nis2-dora-how-to-turn-onboard-cybersecurity-compliance-into-a-competitive-advantage","status":"publish","type":"post","link":"https:\/\/preprod25.numeum.fr\/en\/cra-nis2-dora-how-to-turn-onboard-cybersecurity-compliance-into-a-competitive-advantage\/","title":{"rendered":"CRA, NIS2, DORA: how to turn onboard cybersecurity compliance into a competitive advantage"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>European legislation requires manufacturers to ensure product safety right from the design stage. Numeum and Embedded France have published a white paper to demystify the requirements and provide companies with the tools they need, from risk analysis to certification. <\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">The new white paper on embedded cybersecurity aims to raise awareness of the importance of protection and create new levers for value creation. Proposed by Numeum and <a href=\"https:\/\/www.embedded-france.org\/\" target=\"_blank\" rel=\"noreferrer noopener\">Embedded France<\/a>, the document guides companies through this panorama, using technologies and regulations as cardinal points. <\/p>\n\n<p class=\"wp-block-paragraph\">The white paper is the first step in the work of the Embedded France-led Embedded Cybersecurity Working Group. It pinpoints the particularities, major trends and regulations relating to embedded cybersecurity. <\/p>\n\n<p class=\"wp-block-paragraph\">The objective is clear: to demystify regulations and understand that security is not a tangle but a common goal for :<\/p>\n\n<p class=\"wp-block-paragraph\">1. Making embedded systems safer.<\/p>\n\n<p class=\"wp-block-paragraph\">2. Provide the keys to understanding how to turn these regulations into a strength, and implement cybersecurity right from the design stage.<\/p>\n\n<p class=\"wp-block-paragraph\">The facts are clear. Cybersecurity is now framed by successive regulations, particularly in Europe. Their common objective is to reinforce the security of all digital products, including embedded systems. And for good reason: in a highly digital world, the attack surface is located in these embedded systems.   <\/p>\n\n<p class=\"wp-block-paragraph\">Faced with this reality, Sylvain Guilley, CTO at Secure-IC, points out that the &#8220;<em>regulation is a growth driver. We can no longer make embedded products without integrating cybersecurity&#8221;. <\/em>. In this sense, the Cyber Resilience Act (CRA) presents itself as a foundation for compliance.<\/p>\n\n<p class=\"wp-block-paragraph\">As a reminder, the Cyber Resilience Act (CRA) is a European Union regulation aimed at improving cybersecurity and cyber-resilience. The principle is to establish common cybersecurity standards for products with digital components. Companies, for their part, must comply with these standards, and demonstrate transparency in the creation of their products and equipment.  <\/p>\n\n<p class=\"wp-block-paragraph\">The aim is therefore to improve the cybersecurity of digital elements and hardware, throughout their entire lifecycle.<em>&#8220;The central idea of theCyber Resilience Act is to integrate security right from the design stage of a product<\/em>,&#8221; explains Gerulf Kinkelin, VP Strategy &amp; Business Development at Cetrac.io. To be compliant, a company must therefore carry out cyber-risk assessments, implement a vulnerability management platform, specify an end-of-support date for its products and, ultimately, be able to report any vulnerability within 72 hours. <\/p>\n\n<p class=\"wp-block-paragraph\">Expectations are therefore high, and deadlines are looming. On June 11, 2026,<a href=\"https:\/\/www.enisa.europa.eu\/\" target=\"_blank\" rel=\"noreferrer noopener\">ENISA<\/a> will commission organizations to verify the compatibility of embedded cybersecurity offerings with the regulations. On September 11, every vulnerability will have to be notified. Finally, by December 11, 2027, every organization must comply with the regulations.   <\/p>\n\n<h2 class=\"wp-block-heading\"><strong>IA Act, RED, NIS 2&#8230; a plethora of regulations<\/strong><\/h2>\n\n<p class=\"wp-block-paragraph\">In addition to these obligations, companies are required to comply with a number of other laws and regulations:<\/p>\n\n<p class=\"wp-block-paragraph\">1. The IA Act: to comply, companies must ensure data protection, conduct audits and provide appropriate documentation.<\/p>\n\n<p class=\"wp-block-paragraph\">2. The RED (Radio Equipment Directive): to ensure the safety, compatibility and security of radio equipment.<\/p>\n\n<p class=\"wp-block-paragraph\">3. NIS2: for everything to do with sensitive <a href=\"https:\/\/preprod25.numeum.fr\/industrie\/\">industrial systems<\/a>.<\/p>\n\n<p class=\"wp-block-paragraph\">3. DORA: for the banking and insurance industries.<\/p>\n\n<h2 class=\"wp-block-heading\"><strong>Promoting a proactive approach: Numeum&#8217;s white paper proposes a step-by-step approach<\/strong><\/h2>\n\n<p class=\"wp-block-paragraph\">To take concrete action, the experts recommend acting on 3 dimensions:<\/p>\n\n<p class=\"wp-block-paragraph\">&#8211; Processes. To put in place the means to guarantee robust <a href=\"https:\/\/preprod25.numeum.fr\/cybersecurite\/\" target=\"_blank\" rel=\"noreferrer noopener\">cybersecurity <\/a>. <\/p>\n\n<p class=\"wp-block-paragraph\">&#8211; The products. With security right from the design stage. <\/p>\n\n<p class=\"wp-block-paragraph\">&#8211; Access to the market by obtaining labels and certificates to ensure that the final product meets regulatory and market expectations.<\/p>\n\n<p class=\"wp-block-paragraph\">A step-by-step approach and a robust methodology based on 3 major themes:<\/p>\n\n<p class=\"wp-block-paragraph\">1. An organization that supports IT and OT infrastructures, internal networks and customer interfaces.<\/p>\n\n<p class=\"wp-block-paragraph\">2. A supply chain-based layer to ensure traceability of the measures implemented.<\/p>\n\n<p class=\"wp-block-paragraph\">3. A product layer with a secure architecture to meet real threats.<\/p>\n\n<p class=\"wp-block-paragraph\">In conclusion, certification is a good way to achieve compliance with cybersecurity regulations. Technology thus represents a good way for a company to improve its products, have fine-tuned compliance management and increase its own level of cybersecurity. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>European legislation requires manufacturers to ensure product safety right from the design stage. Numeum and Embedded France have published a white paper to demystify the requirements and provide companies with the tools they need, from risk analysis to certification. <\/p>\n","protected":false},"author":5,"featured_media":10230,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"tags":[2212],"region":[],"thematique":[2213],"secteur_activite":[2862,2203,2204,2860,2202],"vision_geographique":[],"class_list":["post-32558","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","tag-industry-of-the-future","thematique-industry","secteur_activite-cybersecurity","secteur_activite-esn","secteur_activite-ict","secteur_activite-industry","secteur_activite-software-publisher"],"acf":[],"_links":{"self":[{"href":"https:\/\/preprod25.numeum.fr\/en\/wp-json\/wp\/v2\/posts\/32558","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/preprod25.numeum.fr\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/preprod25.numeum.fr\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/preprod25.numeum.fr\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/preprod25.numeum.fr\/en\/wp-json\/wp\/v2\/comments?post=32558"}],"version-history":[{"count":1,"href":"https:\/\/preprod25.numeum.fr\/en\/wp-json\/wp\/v2\/posts\/32558\/revisions"}],"predecessor-version":[{"id":32559,"href":"https:\/\/preprod25.numeum.fr\/en\/wp-json\/wp\/v2\/posts\/32558\/revisions\/32559"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/preprod25.numeum.fr\/en\/wp-json\/wp\/v2\/media\/10230"}],"wp:attachment":[{"href":"https:\/\/preprod25.numeum.fr\/en\/wp-json\/wp\/v2\/media?parent=32558"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/preprod25.numeum.fr\/en\/wp-json\/wp\/v2\/tags?post=32558"},{"taxonomy":"region","embeddable":true,"href":"https:\/\/preprod25.numeum.fr\/en\/wp-json\/wp\/v2\/region?post=32558"},{"taxonomy":"thematique","embeddable":true,"href":"https:\/\/preprod25.numeum.fr\/en\/wp-json\/wp\/v2\/thematique?post=32558"},{"taxonomy":"secteur_activite","embeddable":true,"href":"https:\/\/preprod25.numeum.fr\/en\/wp-json\/wp\/v2\/secteur_activite?post=32558"},{"taxonomy":"vision_geographique","embeddable":true,"href":"https:\/\/preprod25.numeum.fr\/en\/wp-json\/wp\/v2\/vision_geographique?post=32558"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}