Secure by Default
Your product ships in 8 weeks. The technical file says nothing about cybersecurity. Prove it was secure by design.
You are the Lead Firmware Engineer at Kastos IoT. Four weeks have passed since the Zero Day — the authentication bypass that triggered Kastos’s first CRA incident response. The patch shipped. The SBOM was rebuilt. The notified body engagement is underway. Now comes the harder question: can you prove the K400 was secure by design? Your task: produce the technical documentation file required under CRA Article 31 for the K400 v4.0 firmware release. The existing file was written for the Radio Equipment Directive. It covers EMC and RF safety. It says nothing about cybersecurity.
- Kastos IoT — 340 employees, €62M revenue, HQ Rotterdam
- K400 v4.0 firmware release scheduled in 8 weeks
- Current technical file: RED-compliant (EMC + RF safety), no cybersecurity section
- SBOM rebuilt after Module 1 — now verified against build artifacts
- Notified body (BSI Netherlands) engagement underway for Important Class I assessment
- 40% of installer base are small firms that struggle with SSH configuration