Emtract Ingest
API
EN
EN
DE
Dashboard
Regulations
Crawlers
Attributes
Topics
Home
/
Regulations
/
CRA
/
Edit measure
Edit measure
Title (English)
Title (German)
Obligations
Meet the essential cybersecurity requirements for the product
Assess, document and keep updating the cybersecurity risks
Exercise due diligence on third-party components and report vulnerabilities to their supplier
Set the support period and handle vulnerabilities throughout it
Carry out the conformity assessment procedure
Have critical products certified once a Commission delegated act requires it
Draw up the technical documentation and keep it up to date
Draw up the EU declaration of conformity and supply it with the product
Affix the CE marking
Make the product identifiable and provide the manufacturer's details
Designate a single point of contact for users and make it easy to find
Supply user information and instructions and state the end of the support period
Ensure conformity is maintained in series production
Keep the technical documentation and EU declaration of conformity for ten years
Take corrective action, withdraw or recall the product where it is not compliant
Provide documents to the market surveillance authorities and cooperate with them
Identify the economic operators upstream and downstream
Notify the cessation of the manufacturer's operations
Submit an early warning of an actively exploited vulnerability within 24 hours
Submit an early warning of a severe incident within 24 hours
Inform users about vulnerabilities and severe incidents
Importers: verify conformity before placing on the market and provide their own contact details
Distributors: check marking and documents before making the product available
Importers and distributors: report vulnerabilities they become aware of to the manufacturer
Authorised representative: keep the mandate and produce it on request
Open-source software stewards: develop and verifiably document a cybersecurity policy
Important products of class I — internal control only where standards are fully applied
Important products of class II — internal control not available
Submit a vulnerability notification within 72 hours
Submit a final report on an actively exploited vulnerability within 14 days of a corrective measure becoming available
Submit an incident notification within 72 hours
Submit a final report on a severe incident within one month
Description (English)
Remediated vulnerabilities are addressed by security updates provided without delay and, except for tailor-made products, free of charge; updates are distributed securely and accompanied by advisory messages to users.
Description (German)
Behobene Schwachstellen werden durch Sicherheitsaktualisierungen unverzüglich und, sofern es sich nicht um maßgeschneiderte Produkte handelt, unentgeltlich bereitgestellt; die Verteilung erfolgt auf sichere Weise, und die Aktualisierungen sind mit Hinweisen an die Nutzer zu begleiten.
Due date
Cancel
Delete this measure