Emtract Ingest
API
EN
EN
DE
Dashboard
Regulations
Crawlers
Attributes
Topics
Home
/
Regulations
/
CRA
/
Edit measure
Edit measure
Title (English)
Title (German)
Obligations
Meet the essential cybersecurity requirements for the product
Assess, document and keep updating the cybersecurity risks
Exercise due diligence on third-party components and report vulnerabilities to their supplier
Set the support period and handle vulnerabilities throughout it
Carry out the conformity assessment procedure
Have critical products certified once a Commission delegated act requires it
Draw up the technical documentation and keep it up to date
Draw up the EU declaration of conformity and supply it with the product
Affix the CE marking
Make the product identifiable and provide the manufacturer's details
Designate a single point of contact for users and make it easy to find
Supply user information and instructions and state the end of the support period
Ensure conformity is maintained in series production
Keep the technical documentation and EU declaration of conformity for ten years
Take corrective action, withdraw or recall the product where it is not compliant
Provide documents to the market surveillance authorities and cooperate with them
Identify the economic operators upstream and downstream
Notify the cessation of the manufacturer's operations
Submit an early warning of an actively exploited vulnerability within 24 hours
Submit an early warning of a severe incident within 24 hours
Inform users about vulnerabilities and severe incidents
Importers: verify conformity before placing on the market and provide their own contact details
Distributors: check marking and documents before making the product available
Importers and distributors: report vulnerabilities they become aware of to the manufacturer
Authorised representative: keep the mandate and produce it on request
Open-source software stewards: develop and verifiably document a cybersecurity policy
Important products of class I — internal control only where standards are fully applied
Important products of class II — internal control not available
Submit a vulnerability notification within 72 hours
Submit a final report on an actively exploited vulnerability within 14 days of a corrective measure becoming available
Submit an incident notification within 72 hours
Submit a final report on a severe incident within one month
Description (English)
The manufacturer provides for measures to facilitate the sharing of information about potential vulnerabilities and publishes a contact address for reporting them, which also appears in the Annex II user information.
Description (German)
Der Hersteller stellt Maßnahmen bereit, die den Austausch von Informationen über mögliche Schwachstellen erleichtern, und gibt eine Kontaktadresse für die Meldung an, die auch in den Nutzerinformationen nach Anhang II erscheint.
Due date
Cancel
Delete this measure