Regulating Smart Device Support Periods: User Expectations and the European Cyber Resilience Act

Lorenz Kustosch and Carlos Gañán, Delft University of Technology; Mattis van 't Schip, Radboud University; Michel van Eeten and Simon Parkin, Delft University of Technology

Supporting consumer IoT devices with updates is crucial to ensure their security. However, this support period is usually shorter than the device's actual lifespan, resulting in millions of unsupported and vulnerable devices. The upcoming European Cyber Resilience Act (CRA) addresses this by requiring manufacturers to support their products for the expected use time, which should be based on reasonable user expectations. In this work, we thus empirically explore the concept of user expectations regarding smart devices' use times and security provision by conducting a large-scale survey in five EU countries (n = 993). We find that respondents' smart device use times and lifetime expectations exceed the CRA's baseline of five years for a majority of device categories and vary substantially across device categories, their ""smartness"", and individuals. Respondents also consider different factors for the lifetimes of smart and conventional devices. Surprisingly, a majority of respondents expected update support to correspond with devices' full lifetimes, highlighting how the current market dynamics of short support times seem to contrast expectations. Our results provide novel insights for manufacturers and market authorities who will need to determine support periods for smart products in the coming years.

Category: 
Short Presentation

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {309704,
author = {Lorenz Kustosch and Carlos Ga{\~n}{\'a}n and Mattis van {\textquoteright}t Schip and Michel van Eeten and Simon Parkin},
title = {Regulating Smart Device Support Periods: User Expectations and the European Cyber Resilience Act},
booktitle = {34th USENIX Security Symposium (USENIX Security 25)},
year = {2025},
isbn = {978-1-939133-52-6},
address = {Seattle, WA},
pages = {5149--5168},
url = {https://www.usenix.org/conference/usenixsecurity25/presentation/kustosch-regulating},
publisher = {USENIX Association},
month = aug
}