Author (Corporate) | Council of the European Union, European Parliament |
---|---|
Series Title | Official Journal of the European Union |
Series Details | (L) 2024/2847 |
Publication Date | 20/11/2024 |
Content Type | Blog & Commentary, Legislation, News, Policy-making |
Summary:Regulation (EU) 2024/2847 - adopted by the co-legislators on 23 October 2024 - setting out horizontal cybersecurity requirements for products with digital elements. It is also known as the Cyber Resilience Act (CRA). It introduces amendments to Regulation (EU) No 168/2013, Regulation (EU) No 2019/1020 and Directive (EU) 2020/1828. This is a text with EEA relevance. Further information:The cybersecurity of products with digital elements has a strong cross-border dimension. In addition, incidents initially affecting a single entity or Member State often spread within minutes across the entire internal market. While existing legislation applies to certain products, most of the hardware and software products are not yet covered by any framework tackling their cybersecurity. This Regulation lays down rules for the making available on the market of products with digital elements to ensure the cybersecurity of such products. It establishes essential cybersecurity requirements for products design, development and production, and obligations for economic operators in relation to those products with respect to cybersecurity. It sets out essential cybersecurity requirements for the vulnerability handling processes put in place by manufacturers, and related obligations. It lays down rules on market surveillance, including monitoring and enforcement of the requires and requirements. The Act comprises amendments to Regulation (EU) No 168/2013, Regulation (EU) 2019/1020 and Directive (EU) 2020/1828. The draft Regulation was first announced in the European Commission's Cybersecurity Strategy. It was formally adopted by the Commission on 15 September 2022, following the annual State of the European Union (SOTEU) address delivered by the President of the European Commission. The Council of the European Union adopted its general approach to the proposal on 19 July 2023. The relevant committee of the European Parliament adopted its own negotiating position on the same day. An informal agreement between the co-legislators on a compromise text for this file was reached on 30 November. This was formally endorsed by Parliament on 12 March 2024 and by the Council on 10 October. The Act was signed by the co-legislators on 23 October 2024 and published in the Official Journal on 20 November 2024. |
|
Source Link | Link to Main Source http://data.europa.eu/eli/reg/2024/2847/oj |
Related Links |
|
Subject Categories | Internal Markets, Security and Defence |
Subject Tags | Consumer Rights | Protection, Cybersecurity | Cyber-security, Risk | Crisis Management |
International Organisations | European Union [EU] |