The CRA is making security engineering at the embedded Linux level mandatory—and that's an opportunity

emlix Article in Markt&Technik issue 22/2026

The Cyber Resilience Act will take effect in December 2027 and requires end-to-end system and security engineering all the way down to the embedded Linux system level.
In the 22/2026 issue of Markt&Technik, Heike Jordan explains why there cannot be a single, generic CRA implementation: What matters is a product-specific risk analysis, not a checklist to be ticked off. And: Security-by-design isn’t just an extra burden. A consistently hardened system reduces maintenance efforts and—especially for products with lifespans exceeding ten years—significantly lowers total cost of ownership.

Read the article