Microchip Technology Cyber Resilience Act
Microchip Technology Designing for the Cyber Resilience Act demonstrates how the European Union Cyber Resilience Act affects connected hardware, software, and embedded-system development. The resource covers the regulation’s cybersecurity requirements for products with digital elements and the implications for manufacturers selling applicable products in the European Union. Additionally, the act addresses product security, vulnerability management, software updates, and lifecycle responsibilities.
The Microchip resource outlines a security-by-design approach that incorporates cyber-risk assessment, secure product development processes, documentation, and security update planning. It also discusses foundational device-security capabilities such as trusted identities, secure boot, authentication, protected credential storage, secure provisioning, and hardware cryptography.
Microchip supports development via secure authentication ICs, microcontrollers, microprocessors, FPGAs, communication devices, the MPLAB® development ecosystem, and Trust Platform Design Suite. Factory key provisioning, in-field provisioning, firmware programming, and device-management services provide additional options for implementing connected-product security.
Features
- Overview of the EU Cyber Resilience Act and its effect on embedded systems
- Explanation of cybersecurity requirements for products with digital elements
- Guidance for incorporating security into the product-development lifecycle
- Cyber-risk assessment and vulnerability-management considerations
- Security update and product support planning
- Secure boot, authentication, and protected credential-storage guidance
- Secure device identity and provisioning support
- Hardware cryptography and tamper-resistance considerations
- References to ISO/IEC 62443 and ETSI EN 303 645 cybersecurity standards
- Microchip products, tools, and services for supporting CRA readiness
Tech Topics
- Cyber Resilience Act objectives
- Products with digital elements
- Security-by-design principles
- Cybersecurity risk assessment
- Secure product-development processes
- Vulnerability identification and management
- Security patches and software updates
- Product-lifecycle security
- Device identity and authentication
- Secure boot
- Hardware key storage
- Secure provisioning
- Cryptographic operations
- Security documentation
- Supply-chain security
- Embedded product compliance planning
Additional Resources
Infographic
