| ▲ | lnsru a day ago |
| So basically you need 3 persons writing compliance documentation and taking care of cybersecurity. Basically another 200000€ personal cost year in low cost area. 250000€ or more in bigger cities. You have a microprocessor in your product and it’s done deal. No big deal for corporations though. Buddy’s workplace hired new compliance department for this topic with 30 persons. That’s competition european way. |
|
| ▲ | BadBadJellyBean a day ago | parent | next [-] |
| I'd rather have that than insecure hardware. It seems like it forces security to be a first class priority instead of an afterthought. |
| |
| ▲ | lnsru a day ago | parent | next [-] | | The thing is not that the product will be somehow secure. It will have properly filled compliance papers. That’s the same story with functional safety. For example car electronic components break all the time, but they have well done paperwork. | | |
| ▲ | flohofwoe a day ago | parent | next [-] | | > It will have properly filled compliance papers Sounds like a perfect job for AI tbh ;) | |
| ▲ | BadBadJellyBean a day ago | parent | prev [-] | | > The thing is not that the product will be somehow secure. I don't believe that is true. Cars do break but they have to meet safety standards. That doesn't make them perfect but it's much better than not having them. You can't make perfect safety standards in an ever changing world but you can define minimum standards. I understand that documentation is a pain in the butt, but it's necessary to have some oversight. It's part of the enforcement. Everyone has to do it so we know the documentation should exist. That means we can fine companies that don't do it. If you mad the documentation and lied on it and it comes out you will probably fined even more. It's a deterrent and a way to enforce the rules. |
| |
| ▲ | WarmWash a day ago | parent | prev | next [-] | | What you are also saying in the same sentence is "I would rather only buy from megacorporations than small players" | |
| ▲ | logicchains a day ago | parent | prev [-] | | It forces Europeans wanting to build hardware startups to go overseas, so there's even fewer new European hardware companies and Europe becomes even more dependent on the US and China. | | |
| ▲ | BadBadJellyBean a day ago | parent [-] | | Just like everyone left when the GDPR went into place? Having safety standards in place (and yes that also means documenting them) can even be a selling point. To have demonstrably secure hardware according to a standard can be highly desirable. I think losing the companies that don't have security as a main priority isn't too bad. I assume that the EU will create import restrictions if there is a meaningful shift to avoid EU rules. |
|
|
|
| ▲ | inigyou a day ago | parent | prev [-] |
| You know that when a regulation mandates a role like this, it isn't the person's entire job, right? When GDPR says you need a data protection officer, it doesn't mean you need to hire someone to be your data protection officer. In a very small startup, it could mean the CEO is also the data protection officer. |
| |
| ▲ | Muromec 20 hours ago | parent [-] | | You don't need a whole full timer for that either. When we had to deal with the usual iso stuff it was one guy hired through the agency working on Thursdays |
|