CRA, RED, and CS&RRegulations to Secure the Connected World By Francesco Vaiani* | Translated by AI 6 min Reading Time Regulations such as the EU's Cyber Resilience Act and Radio Equipment Directive or the proposed Cyber Security and Resilience Bill in the UK tighten the requirements for connected products. Security by Design, SBOMs, secure updates, and consistent lifecycle management are more important than ever before. With the increasing number of Internet of Things (IoT) and edge devices, potential security vulnerabilities in distributed networks of electronic systems are rising dramatically. To protect their connected devices, companies require effective cybersecurity measures to ensure uninterrupted operations, secure data, and protect application users worldwide. However, as threats constantly evolve, global regulations are also advancing to enforce stricter security standards. Pioneers of this change are the Cyber Resilience Act (CRA) and the Radio Equipment Directive (RED) of the European Union (EU). These standards establish comprehensive minimum cybersecurity requirements that shape global practices in the development of digital and wireless products. Many companies face significant challenges as they must adapt their business strategies to comply with the new regulations. These will apply to most connected devices sold in the EU. Similar guidelines have been proposed or already enacted in other regions; an example is the "Cyber Security and Resilience (CS&R) Bill" proposed in the United Kingdom. Cybersecurity involves protecting devices, networks, firmware, and data from external threats. The primary goal of implementing cybersecurity in IoT applications is to prevent disruptions that could jeopardize operations, safety, or regulatory compliance. However, flaws in devices, outdated firmware, or insecure communication protocols can provide attackers with easy access, allowing them to build botnets, steal data, or gain unauthorized control. The Mirai botnet, for example, brought hundreds of thousands of unprotected IoT devices under its control and overwhelmed targets with large-scale