Emtract Ingest
API
EN
EN
DE
Dashboard
Regulations
Crawlers
Attributes
Topics
Home
/
Regulations
/
CRA
/
Edit obligation
Edit obligation
Title (English)
Title (German)
Kind
Approval
Due Diligence
Governance
Other
Record Keeping
Reporting
Stakeholder Engagement
Frequency
Annual
Biennial
Continuous
Event-triggered
Monthly
One-time
Other
Quarterly
Weekly
Check frequency
Annual
Biennial
Continuous
Event-triggered
Monthly
One-time
Other
Quarterly
Weekly
Rule set
Regulation-wide (no rule set)
Manufacturers of products with digital elements
Manufacturers of products with digital elements, including products already on the market
Authorised representatives of a manufacturer
Importers of products with digital elements
Distributors of products with digital elements
Economic operators — manufacturers, authorised representatives, importers and distributors
Importers and distributors
Manufacturers of critical products with digital elements
Open-source software stewards
Manufacturers, authorised representatives and importers of products with digital elements
Manufacturers of important products with digital elements, class I
Manufacturers of important products with digital elements, class II
Complexity (0–5)
Business functions
Communications
Compliance
Executive
Finance
Human Resources
Legal
Operations
Other
Procurement
Product
Sales
Sustainability
Description (English)
The manufacturer assesses the cybersecurity risks of the product and takes the result into account in planning, design, development, production, delivery and maintenance. The assessment is documented, kept up to date throughout the support period and included in the technical documentation.
Description (German)
Der Hersteller bewertet die Cybersicherheitsrisiken des Produkts und berücksichtigt das Ergebnis in Planung, Konzeption, Entwicklung, Herstellung, Lieferung und Wartung. Die Bewertung umfasst mindestens eine Analyse auf der Grundlage der Zweckbestimmung und der vernünftigerweise vorhersehbaren Verwendung, etwa der Betriebsumgebung und der zu schützenden Anlagen, und berücksichtigt die voraussichtliche Nutzungsdauer. Sie gibt an, ob und wie die Anforderungen des Anhangs I Teil I Nummer 2 anwendbar sind und wie sie umgesetzt werden. Die Bewertung wird während des Unterstützungszeitraums dokumentiert, fortgeschrieben und in die technische Dokumentation aufgenommen. Alle relevanten Cybersicherheitsaspekte einschließlich bekannt gewordener Schwachstellen sind systematisch zu dokumentieren.
Affected products/services (English)
All products with digital elements the company makes available on the Union market.
Affected products/services (German)
Alle Produkte mit digitalen Elementen, die das Unternehmen auf dem Unionsmarkt bereitstellt.
Checking responsibility (English)
Product development and product security, supported by the compliance function.
Checking responsibility (German)
Produktentwicklung und Produktsicherheit, fachlich begleitet von der Compliance-Funktion.
Check method (English)
Documented risk analysis per product or product family, filed in the technical documentation.
Check method (German)
Dokumentierte Risikoanalyse je Produkt oder Produktfamilie, abgelegt in der technischen Dokumentation.
Withdrawn at
Cancel
Delete this obligation