{"id":19031,"date":"2024-12-16T21:00:00","date_gmt":"2024-12-16T20:00:00","guid":{"rendered":"https:\/\/www.rosello-mallol.com\/?p=19031"},"modified":"2024-12-16T16:58:36","modified_gmt":"2024-12-16T15:58:36","slug":"cyberresilience-act","status":"publish","type":"post","link":"https:\/\/www.rosello-mallol.com\/en\/cyberresilience-act\/","title":{"rendered":"Cyberresilience Act, how it affects your business?"},"content":{"rendered":"\n
On December 10, 2024, the new law came into force REGULATION (EU) 2024\/2847<\/a>OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 23 October 2024 on horizontal cybersecurity requirements for products containing digital elements and amending Regulation (EU) No 168\/2013 and Regulation (EU) 2019\/1020 and Directive (EU) 2020\/1828 (Cyberresilience Act)<\/p>\n\n\n\n In the age in which we live, where everyone is digitally connected, it must be taken into account that all products with digital elements integrated into an electronic information system can serve as transmitters of an attack for malicious actors. Consequently, even the least critical equipment and software can facilitate the initial compromise of a device or network, allowing malicious actors to gain privileged access to a system or move laterally between systems.<\/p>\n\n\n\n The Cyberresilience Act aims to set boundary conditions that enable the development of products with secure digital elements, ensuring that products consisting of computer hardware and software are placed on the market with fewer vulnerabilities. It also aims to create conditions that enable users to take into account the cybersecurity<\/a> when choosing and using products with digital elements<\/p>\n\n\n\n The Cyberresilience Act sets out a number of essential cybersecurity requirements for the design, development and manufacturing of products with digital elements and for the vulnerability management process, as well as rules for placing products with digital elements on the market and rules on market surveillance.<\/p>\n\n\n\n Below, we will look at the most important obligations that this regulation imposes on manufacturers, importers and distributors of products with digital elements.<\/p>\n\n\n\n What obligations does the Cyberresilience Act impose?<\/strong><\/p>\n\n\n\n Obligations for Manufacturers<\/strong><\/p>\n\n\n\n When placing a product containing digital elements on the market, manufacturers shall ensure that the product has been designed, developed and produced in compliance with the essential cybersecurity requirements set out in that Regulation.<\/p>\n\n\n\n Manufacturers shall carry out a cybersecurity risk assessment associated with a product containing digital elements and take into account the outcome of this assessment during the planning, design, development, production, delivery and maintenance phases of the product, with the aim of minimising cybersecurity risks, preventing incidents and minimising their impact, including those related to the health and safety of users. This risk assessment must be included in the technical documentation for the product.<\/p>\n\n\n\n Manufacturers shall ensure that each security update made available to users during the support period remains available after its release for a minimum period of ten years or for the remainder of the support period, if this is longer.<\/p>\n\n\n\n Manufacturers shall ensure that products containing digital elements are accompanied by user information and instructions, in paper or electronic form. Such instructions and information shall be provided in a language easily understood by users and market surveillance authorities. They shall be clear, comprehensible, intelligible and legible.<\/p>\n\n\n\n Obligations for Importers:<\/strong><\/p>\n\n\n\n Importers shall only place on the market products with digital elements that meet the essential cybersecurity requirements and provided that the processes established by the manufacturer meet the essential cybersecurity requirements.<\/p>\n\n\n\n Importers shall indicate their name, registered trade name or trademark, postal address, e-mail address or other digital contact details and, where applicable, the website where they can be contacted on the product containing digital elements, on its packaging or in a document accompanying the product. The contact details shall be provided in a language easily understood by end-users and market surveillance authorities.<\/p>\n\n\n\n Before placing a product containing digital elements on the market, importers shall ensure that:<\/p>\n\n\n\n Obligations for Distributors<\/strong><\/p>\n\n\n\n Before marketing a product with digital elements, distributors must verify that:<\/p>\n\n\n\n a) The product bears the CE marking;<\/p>\n\n\n\n b) The manufacturer and the importer have complied with the obligations mentioned above and set out in the Regulation.<\/p>\n\n\n\n Creating a single notification platform<\/strong><\/p>\n\n\n\n For the purposes of notifications of vulnerabilities in products containing digital elements, as well as serious incidents impacting the security of such products and in order to simplify notification obligations for manufacturers, ENISA will create a single notification platform.<\/p>\n\n\n\n Requirements that products with digital elements must have<\/strong><\/p>\n\n\n\n On the other hand, as we have said before, the Regulation also tells us the requirements that products with digital elements must apply in order to be marketed, these are:<\/p>\n\n\n\n Technical documentation<\/strong><\/p>\n\n\n\n The Cyberresilience Act also tells us that it must contain the technical documentation, which is as follows:<\/p>\n\n\n\n The technical documentation shall contain all relevant data or details relating to the means used by the manufacturer to ensure that the product with digital elements and the processes established by the manufacturer comply with the essential cybersecurity requirements.<\/p>\n\n\n\n The technical documentation shall contain at least the following information:<\/p>\n\n\n\n For more information see this post<\/a> from European Commission.<\/p>\n\n\n\n Author: Mariona Heredia<\/strong>, Lawyer.<\/p>\n\n\n\n If you need more informarion, contact us!<\/p>\n\n\n\n <\/p> \n
\n
\n
\n
<\/ul><\/div>\n