EU Cyber Resilience Act

General News

Summary

On September 15, 2022, the European Commission published its Proposal for a Cyber Resilience Act (CRA) which sets out new requirements for hardware and software products in the EU. • Manufacturers will need to assess the cyber risk of their digital hardware and software and take continued action to fix problems during the lifetime of the product. These notice requirements apply regardless of whether the incident would constitute a data breach under applicable privacy laws. • EU Member State authorities will be permitted to monitor compliance with the CRA, and maximum fines of up to EUR 15 million (approx. • The CRA specifies further cybersecurity requirements for products, including requirements for products to be delivered with a secure by default configuration, ensure appropriate access control mechanisms, protect availability of essential functions (including protection against, and mitigation of, denial of service acts), and be designed to reduce the impact of a security incident.

Classifications

industries
No industries detected
applications
Security

AskAI Classifications

Labels
No AI classifications detected

Linked Companies