Cybersecurity Regulation
Cybersecurity rules increasingly require secure-by-design products, vulnerability management, and lifecycle evidence without prescribing a processor technology.
Product and service providers are being asked to manage cybersecurity across design, development, deployment, support, and incident response. Memory safety can affect that work, but using CHERI does not by itself establish compliance.
Examples of current regimes
European Union Cyber Resilience Act
The Cyber Resilience Act entered into force on 10 December 2024 and covers products with digital elements. Its reporting obligations apply from 11 September 2026, and its main obligations apply from 11 December 2027. Manufacturers should use the official implementation material to determine scope, classification, conformity assessment, support-period, and reporting duties.
United Kingdom consumer connectable products
The UK’s Product Security and Telecommunications Infrastructure product-security regime has applied since 29 April 2024. It places duties on manufacturers, importers, and distributors of relevant consumer connectable products and includes baseline security requirements and statements of compliance.
Operators of essential and important services
The EU NIS2 framework addresses cybersecurity risk management and incident reporting for covered sectors and entities. National implementation and sector rules determine the exact obligations. Other jurisdictions have their own critical-infrastructure regimes.
Relating CHERI to an obligation
Regulation is usually outcome-based. A useful compliance mapping therefore connects:
- a legal or standard requirement;
- the product risk and threat being controlled;
- the CHERI property used, such as bounded access or least-authority compartments;
- implementation and test evidence;
- residual risk and supporting controls;
- lifecycle ownership and change management.
CHERI may help a manufacturer show that it addressed a recurring vulnerability class and designed containment into a product. It does not supply vulnerability disclosure, software updates, conformity assessment, documentation, monitoring, or incident reporting.
Use current legal advice
Regulatory scope depends on the product, market, role, and date. This overview is not legal advice. Consult the current official text, relevant authority, and qualified advisers for a compliance decision.
