Skip to main content
๐ŸŽค Speaking at KubeCon EU 2026 Lessons Learned Orchestrating Multi-Tenant GPUs on OpenShift AI View Session
๐ŸŽค Speaking at Red Hat Summit 2026 GPUs take flight: Safety-first multi-tenant Platform Engineering with NVIDIA and OpenShift AI Learn More
CRA Impact on SIEM and Security Management Systems (EN 304 622)
DevOps

CRA Impact on SIEM Systems (EN 304 622)

SIEM systems are Important Products Class II โ€” requiring potential third-party assessment. What security management platform vendors need to know.

LB
Luca Berton
ยท 1 min read

SIEM Under CRA Class II (EN 304 622)

Security Information and Event Management systems are classified as Important Products Class II โ€” the second-highest classification. This reflects the critical role SIEMs play in organizational security.

Why Class II?

A compromised SIEM is catastrophic:

  • Attackers can hide their tracks by manipulating security logs
  • False negatives mean real attacks go undetected
  • Sensitive security data could be exfiltrated
  • Undermines the entire security monitoring infrastructure

Key Requirements

Log Integrity

  • Cryptographic integrity protection for stored logs
  • Tamper-evident log storage
  • Secure log transport (TLS, mutual authentication)
  • Access controls on log data

Detection Quality

  • Documented detection capabilities and coverage
  • Regular rule/signature updates (signed)
  • False positive/negative rate documentation
  • Threat intelligence integration

Availability

  • High availability architecture
  • Graceful degradation under load
  • Alert on SIEM health issues
  • No security gaps during updates

Conformity Assessment

Class II products may require third-party assessment. SIEM vendors should:

  1. Engage with ETSI EN 304 622 development
  2. Plan for potential third-party certification costs (โ‚ฌ20K-100K)
  3. Begin conformity documentation now
  4. Prepare for ongoing assessment as the product evolves

Building or deploying SIEM solutions? I help organizations navigate CRA Class II compliance. Get in touch.

Luca Berton Ansible Pilot Ansible by Example Open Empower K8s Recipes Terraform Pilot CopyPasteLearn ProteinLens TechMeOut