If a product uses OTA updates, what does the CRA require from the security of that mechanism?
The CRA requires the OTA path to be secure enough to distribute updates so vulnerabilities are fixed or mitigated in a timely manner.
It does not prescribe one single technical architecture, but it does require secure update-distribution mechanisms. Read together with the CRA's requirements to protect commands, programs and configuration against unauthorised manipulation, the OTA channel and package handling cannot be left unsecured.
ETSI update-security standards make this more concrete for OTA implementations by pointing to secure channels, authenticated communication partners, and authenticity and integrity checks for updates.
Supports the need to protect configuration, commands, and update distribution against unauthorised manipulation.
Supports authenticity and integrity verification for software updates delivered over a network interface.
Supports secure-channel and update-verification expectations for OTA updates on smart voice-controlled devices.