NON-PAPER
This paper is distributed solely for discussion purposes. It reflects an independent analytical perspective and is not presented on behalf of any organization, body, or regulatory authority.
1. Setting the Context
The convergence of the EU Cyber Resilience Act, NIS2, DORA, and national implementations such as BSI TR-02102 creates a compliance landscape for which many organizations with long-standing embedded product lines are structurally unprepared - not due to a lack of technical solutions, but due to a lack of a common approach that integrates technical capability, budgetary autonomy, and risk appetite into a single, actionable timeline.
This is not a failure of any single function, company, or industry. It is the predictable result of three decades of technological decisions, each made under different circumstances, that are now converging on a regulatory deadline that does not distinguish between historical legacy issues and current negligence. Treating this convergence as a blame game is counterproductive: it encourages concealment over disclosure and inaction over incremental progress.











