>>ahuber+(OP)
There is a lot of talk about who this regulation is supposed to cover, but not a lot about what it actually requires if it covers you. The best I could find after a couple quick searches was that you're supposed to provide information about the security mechanisms used and regular security updates over the lifetime of the product. Is there anything else? This doesnt sound terribly hard to comply with at first glance.