All news

25 August 2026 / 13 minutes of reading

Why We Don’t Think of a TV as a Computer and What the CRA Will Do About It – An Ethical Hacker’s Perspective

What do we think about the CRA after years of taking connected devices apart? Did the CRA arrive at the right time? Will it change anything for ordinary users? And where will it face the greatest practical challenges?


We have written two articles about the Cyber Resilience Act: an overview of the obligations and a detailed analysis of the reporting requirements. Both explain what the regulation says. This article is about something else – what we think about it after years of taking connected devices apart. Did the CRA arrive at the right time? Will it change anything for ordinary users? And where will it face the greatest practical challenges?

This is an opinion piece, not an interpretation of the regulation. If you are looking for information about what the CRA requires and who it applies to, start with our overview of the Cyber Resilience Act. If you are dealing with the reporting obligations that apply from 11 September, we have a separate article on that topic.

Did the CRA Arrive Too Late or Too Early?

Too late from a management perspective, too early in practical terms.

Too Late: The Problem Is More Than Ten Years Old

When the Mirai botnet took down parts of the internet in 2016 using home cameras and routers with factory-set passwords, it became clear that manufacturers’ goodwill would not solve the security problems of connected devices. We still encounter default passwords that provide administrative access to routers and cameras today.

Regulation has caught up with this reality, but more than a decade later. Moreover, the CRA largely consolidates requirements that already existed in a fragmented form: the United Kingdom has the PSTI regime, while the EU has the delegated act supplementing the Radio Equipment Directive and the EN 18031 standard.

Too Early: The Rules Apply, but the Standards Are Not Ready

As of 9 August 2026, not a single harmonised standard relating to the CRA had been cited in the Official Journal of the European Union. This means that the presumption of conformity under Article 27 is unavailable for any product category. Companies are currently designing their products according to draft standards whose wording may still change. In July 2026, the Commission also proposed postponing the deadlines for delivering the standards by two months.

So this is not a debate about “too early versus too late”. It is about the difference between the speed of lawmakers and the speed of the infrastructure responsible for translating the law into specific technical steps. The requirements apply, but the instructions for meeting them are not yet ready.

 

Despite this, I do not believe that the CRA is unnecessary. It introduces something that has been missing until now – consequences. Until now, product security depended on whether a manufacturer was willing to address it. From now on, it will be a condition for placing a product on the market at all.

8 questions. 2 minutes. A clear answer.

Does the Cyber Resilience Act apply to your product? A quick online assessment will show you your role, which product category it belongs to and which obligations apply to you.

At the end, you will receive a one-page overview with a clear verdict, key deadlines and a list of steps you still need to take. Assess each product separately.

Start the quick assessment

Why We Don’t Think of a TV as a Computer

The difference lies in what people perceive as a computer. Phones and laptops qualify – people expect them to receive updates. In their minds, televisions, routers and watches are appliances. Nobody thinks about the firmware running in their washing machine.

The Router: A Device Nobody Is Responsible For

The router is the gateway to the entire household and, at the same time, the most common target for an attacker trying to gain access to the internal network. It is also a device that the average person never logs into throughout its entire lifetime.

Yet nobody seems to be responsible for it. The user assumes that the operator who supplied the device is taking care of it, while the operator considers it the customer’s device.

Consumer Electronics Are Disproportionately Vulnerable

According to a 2025 report by Bitdefender and NETGEAR, the most frequently targeted categories are streaming devices (25.9%), smart TVs (21.3%) and IP cameras (8.6%). Together, they account for more than half of all detected IoT vulnerabilities.

What becomes more interesting is what these figures reveal when placed side by side. Smart TVs account for 9.5% of connected household devices but 21.3% of vulnerabilities. Streaming devices account for 7.3% of devices but 25.9% of vulnerabilities. It is therefore not because there are so many of these devices. It is because they are disproportionately vulnerable – they often remain unpatched and are rarely updated.

And 99.4% of attacks on IoT devices target known vulnerabilities for which manufacturers released fixes long ago. The problem is therefore not unknown flaws, but the fact that devices are not being updated.

It Is Not Ignorance, but Information Asymmetry

Even a motivated buyer cannot currently find out how long a television will receive security updates. That information simply is not provided on the packaging. Yet people commonly keep their televisions for five to eight years – long after updates have stopped. This is precisely what the CRA changes by requiring the support period to be declared.

When It Comes to Watches, People Are Worried About the Wrong Thing

People ask where their data is being sent, but the vulnerabilities we actually find tend to be elsewhere – in the mobile application or cloud API, where it may be possible to access another person’s account, or in unauthenticated Bluetooth pairing.

Educating users is not the solution. We have been trying that for twenty years, and it has not worked. The solution is to shift responsibility to manufacturers – and that is what the CRA does.

What the CRA Will Actually Improve

The regulation’s greatest strength is not any individual technical requirement, but the fact that product security will, for the first time, have direct economic consequences. Without conformity, there is no CE marking, and without CE marking, there is no access to the EU market. Until now, security has been treated as a cost item with no measurable return.

1. Enforcement Will Come from Customers, Not Authorities

Large manufacturers are already pushing requirements down their supply chains through contracts, well before the statutory deadline, and requiring suppliers to confirm compliance with the CRA. This mechanism is faster and tougher than any inspection: when a small company loses an order, it reacts within weeks, not years.

2. The Support Period as a Competitive Parameter

The obligation to declare the support period means that manufacturers will begin competing on product lifespan, not only on price. It is the first genuine counterweight to disposable IoT devices that stop receiving updates one year after purchase. This opens up possibilities that do not exist today – meaningful security criteria in public tenders or the ability to compare two suppliers based on something other than marketing claims.

3. There Will Finally Be Someone to Report a Vulnerability To

From the perspective of our work, the most important requirement is the obligation to establish a coordinated vulnerability disclosure process. Today, the greatest obstacle to reporting vulnerabilities is that the person who finds one has nobody to contact. The report ends up in a general sales inbox without a response – or is followed by a legal letter accusing you of attacking the device.

The regulation will require both a point of contact and a defined process. In practice, this means one thing: a greater proportion of reported vulnerabilities will actually be fixed.

Finally, the 24-hour reporting deadline will require organisations to develop detection capabilities. You cannot report something you do not know about.

Where It Will Face Problems

1. The Rules Are Not Yet Complete

No harmonised standard has been cited, the presumption of conformity is unavailable, and deadlines are being postponed. Companies are designing products according to draft standards while facing the risk that the wording may still change.

2. Company Size Versus the Cost of Compliance

The entity expected to meet the requirements often has five developers and no dedicated security specialist. When you compare the cost of achieving compliance for an entire product line with the margin on a device that sells for forty euros, the likely result is that some products will simply disappear from the EU market. Reduced choice and higher prices are part of the bill.

3. Legacy Portfolios Without an Update Channel

The reporting obligation also applies to devices designed eight years ago that have no mechanism for remote updates. An update mechanism cannot be retrofitted to a device that has already been sold.

4. Supply Chains and Binary Blobs

You cannot create an SBOM for a binary blob supplied by a chipset manufacturer that refuses to disclose its contents. The weakest link is often a third-tier supplier that has never heard of the CRA.

5. Compliance Theatre

From our perspective, this is the greatest professional risk posed by the entire regulation: a device with CE marking, flawless documentation and the same vulnerability we found in it a year ago.

What Does This Mean?

The CRA will not solve the security problems of connected devices on its own. It will, however, solve one problem that has persisted until now: security will no longer depend on whether the manufacturer is willing to address it. For an issue that has been tackled through appeals and recommendations for ten years, that is a significant change.

The rest will depend on whether companies use the coming year to build the capability to technically verify their products – or to produce documentation claiming that they have verified them.

Author: Denis, penetration tester at Citadelo

Legal notice: This article is an opinion piece and does not constitute legal advice.

logo

Sign up for our newsletter for all the important cybersecurity and ethical hacking news.

© 2024 citadelo AG. All rights reserved.

facebooklinkedinxyoutube