As of September 11, manufacturers of products with digital elements are legally obliged to report significant vulnerabilities and incidents that impact the security of their products, as the Cyber Resilience Act (CRA) comes into force.
The legislation introduces mandatory cybersecurity requirements for products with digital elements placed on the EU market.
Under the Regulation, manufacturers who become aware of an actively exploited vulnerability or a severe incident affecting the security of a product with digital elements must report that information through the EU’s Cyber Resilience Act (CRA) Single Reporting Platform.
Initial notifications are required within 24 hours of becoming aware of a reportable event, followed by additional reporting in line with the requirements of the Regulation.
The CRA aims to establish a common framework for improving the cybersecurity of products with digital elements throughout their lifecycle, helping to ensure that cybersecurity is considered from design and development through to maintenance and support.
The National Cybersecurity Centre (NCSC) has published new guidance to support manufacturers in meeting the new requirements.
The guidelines provide practical information on reporting thresholds, timelines, notification procedures, and the information required when submitting reports.
Dr Richard Browne, Director General of the National CybersecurityCentre, said: “The commencement of the Cyber Resilience Act’s reporting obligations will improve visibility of vulnerabilities and incidents affecting connected products and strengthen our collective ability to respond to emerging cyber threats.
“The National CRA Guidelines have been developed to help organisations understand what is expected of them and to support timely and effective compliance. We encourage all manufacturers and relevant economic operators to familiarise themselves with the requirements and ensure that the necessary reporting and vulnerability management processes are in place.”
Commenting on the launch of the guidelines, Minister for Justice, Home Affairs and Migration, Jim O’Callaghan, said: “The Cyber Resilience Act represents a major advancement in protecting citizens, businesses and public services from cyber threats.”
“By embedding security requirements into products from the outset and ensuring that significant vulnerabilities and incidents are reported promptly, the Act will help create a safer and more resilient digital ecosystem across Europe. The National CRA Guidelines provide practical and welcome support to organisations as these important new obligations take effect.”




Add Comment