r/Supernote • u/AnderlAnduel • 45m ago
How is Supernote planning to handle the EU Cyber Resilience Act? Is the "ship features via updates" strategy at risk?
Hey everyone,
I've been thinking about a question related to the EU Cyber Resilience Act (CRA) and wanted to see if anyone from Supernote — or anyone with solid knowledge of the regulation — can weigh in.
Quick context for anyone who hasn't followed this: the CRA has been in force since December 2024. Vulnerability-reporting obligations kick in starting September 2026, and from December 11, 2027, all "products with digital elements" newly placed on the EU market must be fully compliant (CE marking, a duty to provide security updates for the expected lifetime of the product — at least 5 years — documented vulnerability management, etc.).
Supernote has built a lot of its reputation on rolling out new features gradually via firmware updates rather than shipping everything finished out of the box.
My question: what happens to that strategy once the CRA is in full effect?
Devices placed on the market before December 11, 2027 don't need to be retroactively made CRA-compliant — unless there's a "substantial modification." What exactly counts as a "substantial modification" isn't fully settled yet; the EU is still rolling out guidance documents on this.
If a major functional update (new AI features, new connectivity, bigger system changes) were classified as a "substantial modification," Supernote would have to bring that device into full CRA compliance retroactively (conformity assessment, documentation, possibly a new CE mark).
Pure security patches are presumably not affected, but the line between "just a bugfix/security patch" and "functional expansion" has often been pretty blurry with Supernote's updates.
So does this mean that once the CRA is fully in effect, already-sold devices will keep getting security patches but effectively stop getting real new features, because that would open up a compliance can of worms? And would new devices launched after 2027 need to ship complete from day one, since the "deliver later via update" approach becomes too much of a regulatory risk/burden?
Would love to hear from Supernote directly, or from anyone who understands the CRA in more depth. A lot of us bought into this ecosystem partly because of the active update policy, so an official statement on the long-term strategy would be genuinely useful.