Cybersecurity Regulation

Cybersecurity regulation increasingly expects secure-by-design products and lifecycle risk management; CHERI can support those outcomes without constituting compliance on its own.

Cybersecurity law increasingly places responsibility for product and service risk across design, development, deployment, support, and incident response. Most regimes define outcomes and responsibilities rather than prescribing a processor architecture.

CHERI can be relevant because memory safety and containment affect those outcomes. It can reduce exposure to a recurring vulnerability class and provide technical evidence that a component’s access is restricted. It does not, by itself, establish compliance.

European Union Cyber Resilience Act

The Cyber Resilience Act covers products with digital elements placed on the European Union market. It introduces cybersecurity requirements across planning, design, development, maintenance, vulnerability handling, and information supplied with products.

The Act entered into force on 10 December 2024. Its reporting obligations apply from 11 September 2026, and its main obligations apply from 11 December 2027.

CHERI may contribute to a product’s risk treatment by preventing many invalid memory accesses and containing selected components. The Act also covers activities that CHERI does not provide, including cybersecurity risk assessment, vulnerability handling, support periods, documentation, reporting, and conformity assessment.

United Kingdom consumer connectable products

The UK’s Product Security and Telecommunications Infrastructure product-security regime has applied since 29 April 2024. It places duties on manufacturers, importers, and distributors of relevant consumer connectable products and sets baseline requirements concerning passwords, vulnerability reporting, and information about security-update periods.

CHERI is not a requirement of that regime. Its relevance is indirect but practical: connected products often contain memory-unsafe firmware and exposed protocol code, and capability protection can reduce the risk that one malformed input leads to wider access inside the device.

Essential and important services

The European Union’s NIS2 framework addresses cybersecurity risk management and incident reporting for covered sectors and entities. National implementation determines the exact obligations.

For essential and important services, CHERI can contribute to prevention and containment inside devices, gateways, infrastructure software, and operational systems. Availability, recovery, supply-chain security, monitoring, and incident management remain broader service properties.

How CHERI relates to regulatory evidence

A CHERI implementation can provide evidence at several levels:

That evidence can support a wider account of secure design and risk reduction. It does not replace legal interpretation or establish that every requirement has been met.

The boundary of the claim

Regulatory scope depends on the product, market, organisation’s role, sector, and date. Official texts and competent authorities remain the sources for current obligations. This page explains how CHERI’s technical properties can relate to regulatory outcomes; it is not legal advice.

Where next

Critical Infrastructure & Resilience

Critical-infrastructure policy connects prevention and containment with the availability and recovery of essential services.

Continue